Package classified as malware due to code obfuscation, use of eval() for code execution, and a low number of published versions. The file lib/lib.js contains same obfuscated malware dropler as malicious react-refresh-update package, the author is same for both pacakge.
-= Per source details. Do not edit below this line.=-
The package @jaime9008/math-service was found to contain malicious code.
{
"malicious-packages-origins": [
{
"import_time": "2026-03-23T05:14:04.40449964Z",
"sha256": "315f0c2985d7efd218ed894e26a5917599eb63768aaadf1efcae37a4b05f8d11",
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
],
"source": "amazon-inspector",
"modified_time": "2026-03-23T05:11:41Z"
}
]
}