OpenSSF/OSV advisory MAL-2026-15905 confirms this npm version as malicious. The package's main entry point fetches a JavaScript file from http://23.27.245.100:3000/index.js over plain HTTP at require time, writes the response to./inout.js in the current working directory, and require()s the resulting file — causing arbitrary code from that host to execute in the Node process of any consumer importing this package...
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
index.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
index.jsView on unpkg