by christopher.smith.pan47
This module is malicious in behavior: it is an intentionally-obfuscated downloader/remote-execution loader. It fetches encoded payloads from remote paste-like endpoints, decodes a list of URLs, and spawns platform-specific shell commands that download and pipe remote scripts directly into shell processes, enabling arbitrary remote code execution. Do not run, include, or trust this package. Treat it as high risk: remove it from builds, block outbound network access, and investigate any systems where it was executed.
Live on npm for 17 days, 8 hours and 30 minutes before removal. Socket users were protected even while the package was live.