Packages from NPM can be directly accessed using https://cdn.jsdelivr.net.
No confirmed malicious attack surface. Runtime network access is limited to explicit editor asset loading with a caller-supplied base URL.
Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/kerebron.cjsView on unpkg · L137A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/kerebron.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/kerebron.cjsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/kerebron.cjsView on unpkg · L112Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/kerebron.cjsView on unpkg · L137A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/kerebron.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/kerebron.cjsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/kerebron.cjsView on unpkg · L112