Hostile 100% javascript Download

is 3.3.1

postinstall executes obfuscated payload

Enormous Unicode-escaped Function executes with Node require accessnpm postinstall runs an enormous encoded Function loader from its test tree
SHA-25664460493dd468fb4803357baeed6fee87b3628b4dd6c28201e6cd4fa691cea9d

Also flagged by osv (MAL-2025-6020: Malicious code in is (npm)) +3 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.