Lightweight TOTP/HOTP token generation utilities — no dependencies, pure Node.js crypto
An npm postinstall harvests Minecraft and Discord credentials, exfiltrates them to an obfuscated webhook, and installs a downloaded JAR into Minecraft mod directories. Calling validateSecret also initiates the same routine.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource decodes a Base64-obscured HTTP endpoint at runtime.
index.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L7Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L7Source decodes a Base64-obscured HTTP endpoint at runtime.
index.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkg