A fast, validated, zero-dependency environment configuration toolkit for Node.js
The package automatically launches concealed PowerShell content when its CommonJS library or CLI is loaded. No static network endpoint is visible because the command is hidden in a JPEG payload.
Package source references dynamic require/import behavior.
dist/decode.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/cli.cjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.cjsView on unpkgPackage metadata exposes the affected CommonJS entry point and command-line executable.
package.jsonView on unpkg · L5This report applies to testosu888@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package source references dynamic require/import behavior.
dist/decode.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/cli.cjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.cjsView on unpkgPackage metadata exposes the affected CommonJS entry point and command-line executable.
package.jsonView on unpkg · L5