Low confidence YARA match js_hex_obfuscation. Hex obfuscation can be legitimate. Insufficient evidence to classify as malware.
No verification record available.
The package core-js version 3.47.0 is not classified as malware. The only evidence is a low-confidence YARA rule match (js_hex_obfuscation) in package/modules/es.data-view.set-float16.js. While hex obfuscation can be a technique used in malicious code, it is also used in legitimate JavaScript code for various reasons, such as code compression or protection. Without stronger evidence, it's not possible to classify this package as malware.