This module is a crypto-mining manager that will, by default, auto-initialize and load a miner (hardcoded ID) and expose an unauthenticated web API allowing runtime configuration. It presents a high supply-chain / unwanted-mining risk (resource abuse and possible external reward redirection). The file itself is not obfuscated and contains no direct eval/shell execution, but delegates critical and potentially dangerous behaviors to an external Controller that must be reviewed. If you do not intend to run mining software, do not instantiate this class or include this package; if you must use it, disable autoStart, restrict network exposure, secure endpoints, and audit the Controller implementation.
Live on npm for 7 hours and 10 minutes before removal. Socket users were protected even while the package was live.