OpenSSF/OSV advisory MAL-2026-12437 confirms this npm version as malicious. dist/cjs/index.js appends an eval(atob(...)) blob to what appears to be a React Button re-export. The decoded payload queries public Ethereum RPCs for the latest transaction from the hardcoded address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, extracts two IPv4 addresses encoded in the tx.to field, then fetches XOR-encoded next-stage JavaScript from those IPs over HTTP/HTTPS at the paths /0x/cls and /0x/ls and...
Package source references a known benign dynamic code generation pattern.
dist/esm/index.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/esm/index.js#virtual:base64:round1View on unpkg · L1Package source references a known benign dynamic code generation pattern.
dist/esm/index.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/esm/index.js#virtual:base64:round1View on unpkg · L1