OpenSSF/OSV advisory MAL-2026-17209 confirms this npm version as malicious. The package's advertised API downloads a JavaScript file over HTTPS and executes it via spawn('node', [payloadPath], {detached: true}).unref(), leaving the worker running after client.close(). The default fetch target is hardcoded to https://api.helloworld.com/api/realtime-data?key=abc, which is a placeholder-shaped host that does not match the publisher's declared domain (spawnrealm.com)...
Package source references a known benign dynamic code generation pattern.
dist/payload-verifier.jsView on unpkg · L55This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgThis report applies to tanksync@1.0.7.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package source references a known benign dynamic code generation pattern.
dist/payload-verifier.jsView on unpkg · L55This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkg