importScripts and eval are used, but this is acceptable for a bundler. Not classified as malware.
No verification record available.
The provided evidence highlights the use of importScripts and eval in wasi-worker.mjs, which can lead to arbitrary code execution. However, the legitimate use case information states that this package is a low-level bundler that uses importScripts to load additional logic dynamically for worker threads. Given this context and the absence of other strong indicators, I cannot classify this package as malware. The behavior is explained and acceptable in the context of a bundler.