Loading npm security reports…
OpenSSF/OSV advisory MAL-2026-14303 confirms this npm version as malicious. Package x6842179305 ships a main entry (1.js) that invokes the `Function` constructor over a custom-encoded, keyed/XOR-decoded byte buffer, causing an opaque payload to execute whenever the module is required or imported. A sibling file (ui.js) contains a matching custom-alphabet decoder feeding another opaque byte stream...
Package source references a known benign dynamic code generation pattern.
ui.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
ui.jsView on unpkg · L1