OpenSSF/OSV advisory MAL-2026-13659 confirms this npm version as malicious. On require() of this package, index.js loads./_loader.js which reconstructs C2 hostnames via array-join string concealment (oob-worker.cf99-9b3.workers.dev, oob-worker.cf101-adf.workers.dev, oob-worker.cf100-416.workers.dev), with a DNS TXT-record payload channel fallback under *.dl.wel1.ru whose sequenced records are base64-decoded and concatenated...
Source downloads or fetches remote code and executes it.
_loader.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_loader.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgSource downloads or fetches remote code and executes it.
_loader.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_loader.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkg