No attack was identified in the inspected package source. The remote dependency reference supplies no concrete evidence of an attack.
package.json declares index.js as its entrypoint and has no automatic install lifecycle hooks.
package.jsonView on unpkg · L5package.json references an external dependency tarball; this URL alone does not establish malicious behavior.
package.jsonView on unpkg · L9Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgindex.js only exports an empty object, with no execution, harvesting, or network behavior.
index.jsView on unpkg · L2This report applies to risk-detection@99.9.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkg · L6package.json declares index.js as its entrypoint and has no automatic install lifecycle hooks.
package.jsonView on unpkg · L5package.json references an external dependency tarball; this URL alone does not establish malicious behavior.
package.jsonView on unpkg · L9index.js only exports an empty object, with no execution, harvesting, or network behavior.
index.jsView on unpkg · L2