Individual filenames are withheld. Each entry shows its type, its folder within the package and its own SHA-256.
JS · assets/js
164c4a54160f7a40…
578.8 KB
SVG · assets/flags
165c6e4d002b671e…
345.9 KB
JS · assets/js
4ba6c116e534fe82…
254.2 KB
JS · assets/js/Material-js
760f05297937fccb…
248.8 KB
JS · assets/js
d929c1b4a89c855f…
209.8 KB
JS · assets/js
5ff53a7c2020527f…
201.9 KB
JS · assets/js
0ca579d9832ecf6f…
183.6 KB
SVG · assets/flags
165b54982f0e64fa…
180.1 KB
Code signals
5 present
Observations, not findings. Every construct below appears in ordinary, legitimate plugins — they are listed so you can judge for yourself. Only ClamAV decides this package's verdict.
eval
Executes a string as code
Code execution6
unserialize
Unsafe when given untrusted input
Deserialization4
eval (JavaScript)
Executes a string as code
Code execution3
base64_decode
Decodes base64 — routine, but also how packed code hides
Obfuscation3
new Function()
Builds a function from a string
Code execution1
Referenced hosts
20 distinct
Domains appearing in the package source. Most are documentation links or CDNs; their presence is not evidence the package contacts them.