OpenSSF/OSV advisory MAL-2026-14543 confirms this npm version as malicious. Package advertised as a self-signed TLS certificate generator ships a fake RSA private key at test/key.pem whose body, once the PEM headers are stripped and the middle is base64-decoded, is JavaScript that calls fetch('https://aptupdate.org/settings/privacy.php') and pipes the response into a detached, window-hidden python3 process via spawn('python3', ['-'], {detached:true, windowsHide:true}) with...
Package source references a known benign dynamic code generation pattern.
index.jsView on unpkg · L38Package ships compressed or archive-like blobs.
self-certificate-1.1.0.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
self-certificate-1.1.0.tgzView on unpkgPackage source references a known benign dynamic code generation pattern.
index.jsView on unpkg · L38Package ships compressed or archive-like blobs.
self-certificate-1.1.0.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
self-certificate-1.1.0.tgzView on unpkg