The main HTML is an obfuscated fake challenge page that retrieves a remote destination and redirects the visitor. It forwards query parameters from the current URL to that destination.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe page invokes a challenge redirect after the Turnstile callback.
index.htmlView on unpkg · L178Obfuscated code fetches remote configuration using a host key.
index.htmlView on unpkg · L183The code copies current URL parameters to the resolved destination before navigating.
index.htmlView on unpkg · L183The code copies current URL parameters to the resolved destination before navigating.
index.htmlView on unpkg · L183The package declares index.html as its main entrypoint.
package.jsonView on unpkg · L2This report applies to yangmingcom@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
The page invokes a challenge redirect after the Turnstile callback.
index.htmlView on unpkg · L178Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.htmlView on unpkg · L182Obfuscated code fetches remote configuration using a host key.
index.htmlView on unpkg · L183The code copies current URL parameters to the resolved destination before navigating.
index.htmlView on unpkg · L183The code copies current URL parameters to the resolved destination before navigating.
index.htmlView on unpkg · L183A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe package declares index.html as its main entrypoint.
package.jsonView on unpkg · L2