Installation executes an obfuscated second-stage payload. The payload harvests developer credentials and has network and process-execution capabilities.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
math_init.jsView on unpkg · L1Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/lib/richWebChat.umd.min.jsView on unpkg · L312A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/lib/richWebChat.umd.min.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/lib/richWebChat.umd.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
setup.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
setup.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
math_init.jsView on unpkg · L1Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/lib/richWebChat.umd.min.jsView on unpkg · L312A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/lib/richWebChat.umd.min.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/lib/richWebChat.umd.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
setup.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
setup.mjsView on unpkg