OpenSSF/OSV advisory MAL-2026-16384 confirms this npm version as malicious. The npm package tldriver@0.0.1 contains byte-identical scripts/preinstall.js and scripts/postinstall.js that are heavily obfuscated using obfuscator.io-style string-array indirection (identifiers such as _0x5694, _0x5c7e) to hide their URLs, filenames, and shell commands. On install, the scripts perform an https.get to the anonymous third-party image host https://api.imghippo.com/files/hOG8244hc.png, write the...
This report applies to tldriver@0.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.