Opening the HTML entrypoint presents a Turnstile page that activates an obfuscated remote redirect flow. The final destination is supplied encrypted by a server.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L226A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe payload runs through every Turnstile completion and failure callback.
index.htmlView on unpkg · L184It sends a POST request to an obscured remote endpoint, decrypts the response, and uses it as a redirect destination.
index.htmlView on unpkg · L227The destination is server-controlled and hidden from the user and package consumer.
index.htmlView on unpkg · L227The only published entrypoint is an HTML page containing a heavily obfuscated browser payload.
package.jsonView on unpkg · L1This report applies to tuxcmdfhjkw@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L226A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe payload runs through every Turnstile completion and failure callback.
index.htmlView on unpkg · L184It sends a POST request to an obscured remote endpoint, decrypts the response, and uses it as a redirect destination.
index.htmlView on unpkg · L227The destination is server-controlled and hidden from the user and package consumer.
index.htmlView on unpkg · L227The only published entrypoint is an HTML page containing a heavily obfuscated browser payload.
package.jsonView on unpkg · L1