OpenSSF/OSV advisory MAL-2026-16277 confirms this npm version as malicious. The package ships console.js, which when loaded in a browser on any host matching duel.com fetches https://unpkg.com/x6842179305@1.0.3/1.js and https://unpkg.com/x6842179305@1.0.3/ui.js and executes both via (0, eval)(...). On other hosts it redirects the page to duel.com. The declared main/unpkg entry 1.js is a ~740KB single-line Function("ZU7mhwD", "...") loader built from hex-escaped char arrays and a rotor-style...
Package source references a known benign dynamic code generation pattern.
ui.jsView on unpkg · L1This report applies to xa424234657567@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package source references a known benign dynamic code generation pattern.
ui.jsView on unpkg · L1