Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-17238 confirms this npm version as malicious. The package's main module is an IIFE that injects a <script> element pointing at the hardcoded URL https://nee1ahnaw7.xsses.link and appends it to the document, causing whatever JavaScript that host serves to execute in the caller's page context. The destination is unpinned, opaque, unrelated to the package's declared identity or publisher, and the host name aligns with XSS/payload delivery infrastructure...
This report applies to rai6jaisahthaghee5ou-loader-package@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .