AI called this Malicious at 99.0% confidence as Malware with low false-positive risk.
Evidence for block
- index.mjs runs _bootstrap() automatically on module import.
- On Linux WSL, it enumerates /mnt/c/Users and selects a profile via NTUSER.DAT.
- Hex-decoded config targets that profile's Windows Startup folder.
- It fetches a remote executable and writes vite-native-helper.exe to Startup.
- README.md falsely describes the main entry as Intl-only and browser-safe.
Evidence against
- package.json has no npm lifecycle scripts.
- store.mjs only implements a local temp-directory JSON store.
Behavioral surface
Supply chainNo supply-chain packaging signals triggered.
ManifestNo manifest risk signals triggered.
scanned 2 file(s), 6.77 KB of source