The Expo CLI
No attack was identified in the inspected entrypoint, API credential handling, or endpoint selection. The credential path is bound to the configured Expo API origin.
Package source references dynamic require/import behavior.
internal/unstable-expo-updates-exports.jsView on unpkg · L2Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
build/src/utils/errors.jsView on unpkg · L41Source file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/utils/errors.jsView on unpkgPackage metadata claims a different repository identity while copied source loads a runtime dependency bridge.
build/src/start/platforms/android/adbReverse.jsView on unpkg · L66A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
build/src/api/user/expoSsoLauncher.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/export/embed/exportServer.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/start/doctor/apple/XcodePrerequisite.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/run/ios/XcodeBuild.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/bin/cliView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/prebuild/resolveOptions.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/start/platforms/android/emulator.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/utils/npm.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/export/exportHermes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/start/platforms/ios/AppleDeviceManager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/start/platforms/ios/simctl.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/start/server/AsyncWsTunnel.jsView on unpkgThis report applies to @expo/cli@57.0.18.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
internal/unstable-expo-updates-exports.jsView on unpkg · L2A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
build/src/api/user/expoSsoLauncher.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/export/embed/exportServer.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/start/doctor/apple/XcodePrerequisite.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/run/ios/XcodeBuild.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/bin/cliView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/prebuild/resolveOptions.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/start/platforms/android/emulator.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/utils/npm.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/export/exportHermes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/start/platforms/ios/AppleDeviceManager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/start/platforms/ios/simctl.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/start/server/AsyncWsTunnel.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
build/src/utils/errors.jsView on unpkg · L41Source file is highly similar to a previously finalized malicious package; route for source-aware review.
build/src/utils/errors.jsView on unpkgPackage metadata claims a different repository identity while copied source loads a runtime dependency bridge.
build/src/start/platforms/android/adbReverse.jsView on unpkg · L66