Hostile 92% javascript Download

@nativescript-community/ui-pulltorefresh 2.5.4

Embedded Shai-Hulud malware payload

Detects a supply chain compromise in NPM packages (TinyColor, CrowdStrike etc.)Downloads latest trufflehog release

Also flagged by osv (MAL-2025-47161: Malicious code in @nativescript-community/ui-pulltorefresh (npm)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.