Loading npm security reports…
TypeScript toolkit for reusable utilities.
The default export fetches attacker-controlled code from a hard-coded external IP and executes it. This is runtime remote code execution when the exported function is called.
Source passes code obtained from a remote response into a dynamic execution sink.
index.jsView on unpkg · L6Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgSource passes code obtained from a remote response into a dynamic execution sink.
index.jsView on unpkg · L6Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkg