OpenSSF/OSV advisory MAL-2026-16048 confirms this npm version as malicious. The package presents itself as a console shim (index.js is a verbatim copy of console-browserify with description 'Emulate console for all the browsers'), but also ships library.js and test/sessionCtrl.js which auto-execute a stager on module load via initializeService().catch(...). The stager fetches an opaque blob from a base64-hidden URL (config.API_GATEWAY = 'aHR0cHM6Ly93d3cuanNvbmtlZXBlci5jb20vYi9WNk5CWA=='...
This report applies to punypump@1.2.2.
1.2.4, 1.2.2
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.