OpenSSF/OSV advisory MAL-2026-16048 confirms this npm version as malicious. punypump ships a console-browserify-lookalike shim (index.js) that additionally requires library.js, which auto-executes initializeService() at module load. library.js fetches an encrypted blob from a base64-obfuscated URL that decodes to https://www.jsonkeeper.com/b/V6NBX (a public JSON-paste service used as a mutable payload host), AES-256-CBC decrypts the response with a hardcoded key/salt, and passes the...
Package source references a known benign dynamic code generation pattern.
library.jsView on unpkg · L70This report applies to punypump@1.2.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package source references a known benign dynamic code generation pattern.
library.jsView on unpkg · L70