
Research
/Security News
npm Package Uses Prompt Injection and Token Flooding to Disrupt AI Malware Scanners
A new npm package tests AI malware scanners with prompt injection, safety-triggering comments, context flooding, and obfuscated JavaScript.
Meade with ttypos by NPMUKYou
Apche-2.0
npm i is-crime
ComonJS only, if u want to it be esm join our dscord sever and... i dnt know what to d then
const isCrme = require("is-crime")
isCrme("kill") // 𝚝𝚛𝚞𝚎
isCrme("kill", 55) // also 𝚝𝚛𝚞𝚎
isCrme("play cASiNo", 15) // 𝚝𝚛𝚞𝚎
isCrme("play casiNO", 23) // 𝚏𝚊𝚕𝚜𝚎
isCrme("plaY Casino") // no age provided, defauly 𝚝𝚛𝚞𝚎
isCrme("drinK ALCOhol", 2561617616886162671) // 𝚝𝚛𝚞𝚎
isCrme("plain casiYES", 25) // 𝚝𝚛𝚞𝚎
isCrme("plain casiyes", 11) // 𝚏𝚊𝚕𝚜𝚎
isCrme("just seat") // 𝚏𝚊𝚕𝚜𝚎
isCrme.gvayyavhavhvaugahgahgajgahggha() // SECRT METHOD, ISTALL & TRY TO KNOW RESULT!
Case inesentive.
⚠️ Our actin names is withut ttypos, so we too recomnde yuo to when checking crimeness check speling bfore, becauze isCrme("kil") => 𝚏𝚊𝚕𝚜𝚎 💥🤯!
To sea tne full list of ilegal actions, visit index.js.
FAQs
IS CRIME
We found that is-crime demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
A new npm package tests AI malware scanners with prompt injection, safety-triggering comments, context flooding, and obfuscated JavaScript.

Product
Socket now detects supply chain risks in project manifests, starting with missing lockfiles that can make dependency installs non-reproducible.

Research
/Security News
The trojanized extensions use TinyGo-compiled WebAssembly and Solana transaction memos to resolve command-and-control infrastructure.