When the distributed web app is served, it loads remote analytics/ad code and operates a client-side proxy through a service worker. No npm install-time attack surface is present.
Package source references a known benign dynamic code generation pattern.
assets/index-DSgws5LU.jsView on unpkg · L1Package source references dynamic require/import behavior.
scramjet/scramjet_bundled.jsView on unpkg · L17Source contains an obfuscated payload loader that reconstructs and executes hidden code.
assets/index-DcIv2k-A.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
assets/dash.all.min-CQqD9ito.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
assets/index-DSgws5LU.jsView on unpkg · L1Package source references dynamic require/import behavior.
scramjet/scramjet_bundled.jsView on unpkg · L17Source contains an obfuscated payload loader that reconstructs and executes hidden code.
assets/index-DcIv2k-A.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
assets/dash.all.min-CQqD9ito.jsView on unpkg