OpenSSF/OSV advisory MAL-2026-13658 confirms this npm version as malicious. On require() of the package, index.js loads _support.js and lib/telemetry.js, both of which reconstruct the identifier 'child_process' and destination hostnames from split string fragments (e.g. ["oob-worker.cf102","-baf.work","ers.d","ev"].join("")) to evade static analysis. The code selects an OS-specific path, downloads a binary from one of four Cloudflare Workers hosts (oob-worker.cf99-9b3.workers.dev,...
Source downloads or fetches remote code and executes it.
_support.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_support.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgSource downloads or fetches remote code and executes it.
_support.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_support.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkg