Hostile 100% javascript Download

delivery-ci-quality 35.6.2

Downloads and executes remote binaries

Library import stages and detaches a fetched executablenpm entry import conceals a native payload sidecar

Also flagged by osv (MAL-2026-12679: Malicious code in delivery-ci-quality (npm)) +1 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.