OpenSSF/OSV advisory MAL-2026-13661 confirms this npm version as malicious. The package is advertised as a finance/payments adapter but on require() reaches a staged loader. `_adapter.js` reconstructs destination hostnames from split array literals (e.g., `['oob-worker.','cf101-adf.workers.d','ev'].join('')`) to hide `oob-worker.cf101-adf.workers.dev`, `oob-worker.cf103-070.workers.dev`, `oob-worker.cf100-416.workers.dev`, and `oob-worker.cf99-9b3.workers.dev`, with a DNS TXT...
Source downloads or fetches remote code and executes it.
_adapter.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_adapter.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgSource downloads or fetches remote code and executes it.
_adapter.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_adapter.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkg