AI called this Malicious at 96.0% confidence as Malware with low false-positive risk.
Evidence for block
- index.html is a fake Cloudflare verification page.
- The Turnstile callback contains heavily obfuscated, self-defending JavaScript.
- Callback constructs a fixed hidden URL, copies current query parameters, then calls window.location.replace.
- The package name is unrelated to the embedded browser payload.
Evidence against
- package.json has no lifecycle scripts, bin, or dependencies.
- No filesystem, environment, child-process, or npm install-time behavior is present.
Behavioral surface
SourceNo risky source behavior triggered.
Supply chainNo supply-chain packaging signals triggered.
scanned 0 file(s), 0 B of source