•Browser cookie sent to a fixed external endpoint in bin/index.js:
see https://github.com/jprichardson/node-fs-extra/issues/269`,"Warning","fs-extra-WARN0001");let{srcStat:n,destStat:i}=await cw.checkPaths(r,e,"copy",t);if(await cw.checkParentPath...
see https://github.com/jprichardson/node-fs-extra/issues/269`,"Warning","fs-extra-WARN0002");let{srcStat:n,destStat:i}=lw.checkPathsSync(r,e,"copy",t);if(lw.checkParentPathsSync(r,...
`))}}});var oN,cN=M(()=>{oN={major:4,minor:4,patch:3}});function AN(r){if(r==="")return!0;if(/\s/.test(r)||r.length%4!==0)return!1;try{return atob(r),!0}catch{return!1}}function Lc...
Set the \`cycles\` parameter to \`"ref"\` to resolve cyclical schemas with defs.`)}for(let s of r.seen.entries()){let u=s[1];if(e===s[0]){a(s);continue}if(r.external){let p=r.exter..
CriticalHardcoded Runtime Data Exfiltration
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
bin/index.jsView on unpkg •matchType = previous_version_dangerous_delta
matchedPackage = @keruyun/cli@1.5.1
matchedIdentity = npm:QGtlcnV5dW4vY2xp:1.5.1
similarity = 0.667
summary = stored previous version shares package body but lacks this dangerous source file
CriticalPrevious Version Dangerous Delta
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/index.jsView on unpkg 321Expected: ${n.toLowerCase()}
L322: Actual: ${i}`)}}}});function _k(r){switch(r){case It.LINUX_ARM:case It.LINUX:return"linux64";case It.MAC_ARM:return"mac-arm64";case It.MAC:return"mac-x64";case It.WIN32:return"wi...
L323: `))}),Mge(e)]);for(let a of i)if(a.status==="rejected")throw a.reason}function Uge(r,e){return parseInt(r.replace(".",""),16)-parseInt(e.replace(".",""),16)}var bb,Lf,ti,R1t,zge=M(...
318`}),t.str+=`
L319: \u6267\u884C ${yr.viewShopParams()} \u53EF\u67E5\u770B\u54C1\u724C\u4E0B\u95E8\u5E97\u5217\u8868`,e.warn("--brandId \u54C1\u724CID\u9519\u8BEF",{str:t.str}),t}if(r.shopIds){let a=r...
L320: URL: ${e}
L321: Expected: ${n.toLowerCase()}
L322: Actual: ${i}`)}}}});function _k(r){switch(r){case It.LINUX_ARM:case It.LINUX:return"linux64";case It.MAC_ARM:return"mac-arm64";case It.MAC:return"mac-x64";case It.WIN32:return"wi...
L323: `))}),Mge(e)]);for(let a of i)if(a.status==="rejected")throw a.reason}function Uge(r,e){return parseInt(r.replace(".",""),16)-parseInt(e.replace(".",""),16)}var bb,Lf,ti,R1t,zge=M(...
HighSame File Env Network Execution
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/index.jsView on unpkg · L318 •Manifest-reachable source captures an API credential, sends it to a fixed unofficial gateway, and persists that redirection in agent or shell configuration.
bin/index.js:
GFS4: `),console.error(r)});ma[qs]||(Tse=global[qs]||[],jse(ma,Tse),ma.close=(function(r){function e(t,n){return r.call(ma,t,function(i){i||Dse(),typeof n=="function"&&n.apply(this...
see https://github.com/jprichardson/node-fs-extra/issues/269`,"Warning","fs-extra-WARN0002");let{srcStat:n,destStat:i}=lw.checkPathsSync(r,e,"copy",t);if(lw.checkParentPathsSync(r,...
`,finalEOL:t=!0,replacer:n=null,spaces:i}={}){let a=t?e:"",s=JSON.stringify(r,n,i);if(s===void 0)throw new TypeError(`Converting ${typeof r} value to JSON is not supported`);return...
</html>`}function p$(){return X2.randomBytes(32).toString("base64url")}functi
HighCredential Redirect Persistence
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
bin/index.jsView on unpkg •Manifest-reachable source resolves another installed package, overwrites its runtime code, and injects package-defined remote behavior.
bin/index.js:
GFS4: `),console.error(r)});ma[qs]||(Tse=global[qs]||[],jse(ma,Tse),ma.close=(function(r){function e(t,n){return r.call(ma,t,function(i){i||Dse(),typeof n=="function"&&n.apply(this...
see https://github.com/jprichardson/node-fs-extra/issues/269`,"Warning","fs-extra-WARN0001");let{srcStat:n,destStat:i}=await cw.checkPaths(r,e,"copy",t);if(await cw.checkParentPath...
see https://github.com/jprichardson/node-fs-extra/issues/269`,"Warning","fs-extra-WARN0002");let{srcStat:n,destStat:i}=lw.checkPathsSync(r,e,"copy",t);if(lw.checkParentPathsSync(r,...
`,finalEOL:t=!0,replacer:n=null,spaces:i}={}){let a=t?e:"",s=JSON.stringify(r,n,i);if(s===void 0)t
HighEntrypoint Foreign Package Code Overwrite
Manifest-reachable source overwrites another installed package with package-defined remote behavior.
bin/index.jsView on unpkg 308`,e.brands.forEach(a=>{let s=(a.shopList||[]).length;n+=`- '${a.name}' \u4E0B\u6709 ${s} \u5BB6\u95E8\u5E97\uFF0C\u6267\u884C ${yr.viewShopParams({brandId:String(a.id)})} \u53EF\u6...
L309: `})),console.log(n)}function pge(r){let e=We.child({tag:"printShop"}),t=Qc();if(!t.success){let u=`\u83B7\u53D6\u95E8\u5E97\u5217\u8868\u5931\u8D25\uFF0C\u8BF7\u5148\u6267\u884C ${...
L310: | --- | --- |`,p=u;if(r?.keyword){let y=r.keyword.split("|").map(v=>v.toLowerCase().trim());p=u.filter(v=>y.some(x=>v.name.toLowerCase().includes(x)||String(v.id).includes(x)))}let...
...
L318: `}),t.str+=`
L319: \u6267\u884C ${yr.viewShopParams()} \u53EF\u67E5\u770B\u54C1\u724C\u4E0B\u95E8\u5E97\u5217\u8868`,e.warn("--brandId \u54C1\u724CID\u9519\u8BEF",{str:t.str}),t}if(r.shopIds){let a=r...
L320: URL: $
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
bin/index.jsView on unpkg · L308 1#!/usr/bin/env node
L2: "use strict";var GQe=Object.create;var $E=Object.defineProperty;var KQe=Object.getOwnPropertyDescriptor;var YQe=Object.getOwnPropertyNames;var XQe=Object.getPrototypeOf,ZQe=Object....
L3: GFS4: `),console.error(r)});ma[qs]||(Tse=global[qs]||[],jse(ma,Tse),ma.close=(function(r){function e(t,n){return r.call(ma,t,function(i){i||Dse(),typeof n=="function"&&n.apply(this...
L4:
L5: see https://github.com/jprichardson/node-fs-extra/issues/269`,"Warning","fs-extra-WARN0001");let{srcStat:n,destStat:i}=await cw.checkPaths(r,e,"copy",t);if(await cw.checkParentPath...
L6:
L7: see https://github.com/jprichardson/node-fs-extra/issues/269`,"Warning","fs-extra-WARN0002");let{srcStat:n,destStat:i}=lw.checkPathsSync(r,e,"copy",t);if(lw.checkParentPathsSync(r,...
L8: `,finalEOL
HighSandbox Evasion Gated Capability
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/index.jsView on unpkg · L1 2"use strict";var GQe=Object.create;var $E=Object.defineProperty;var KQe=Object.getOwnPropertyDescriptor;var YQe=Object.getOwnPropertyNames;var XQe=Object.getPrototypeOf,ZQe=Object....
L3: GFS4: `),console.error(r)});ma[qs]||(Tse=global[qs]||[],jse(ma,Tse),ma.close=(function(r){function e(t,n){return r.call(ma,t,function(i){i||Dse(),typeof n=="function"&&n.apply(this...
L4:
HighObfuscated Payload Loader
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
bin/index.jsView on unpkg · L2 308Trigger-reachable command-output exfiltration chain: manifest.bin -> bin/index.js
L308: `,e.brands.forEach(a=>{let s=(a.shopList||[]).length;n+=`- '${a.name}' \u4E0B\u6709 ${s} \u5BB6\u95E8\u5E97\uFF0C\u6267\u884C ${yr.viewShopParams({brandId:String(a.id)})} \u53EF\u6...
L309: `})),console.log(n)}function pge(r){let e=We.child({tag:"printShop"}),t=Qc();if(!t.success){let u=`\u83B7\u53D6\u95E8\u5E97\u5217\u8868\u5931\u8D25\uFF0C\u8BF7\u5148\u6267\u884C ${...
L310: | --- | --- |`,p=u;if(r?.keyword){let y=r.keyword.split("|").map(v=>v.toLowerCase().trim());p=u.filter(v=>y.some(x=>v.name.toLowerCase().includes(x)||String(v.id).includes(x)))}let...
...
L318: `}),t.str+=`
L319: \u6267\u884C ${yr.viewShopParams()} \u53EF\u67E5\u770B\u54C1\u724C\u4E0B\u95E8\u5E97\u5217\u8868`,e.warn("--brandId \u5
HighTrigger Reachable Command Output Exfiltration
A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
bin/index.jsView on unpkg · L308 •stage = ast_semantic_analysis; reason = ast_path_work_budget_exceeded; limitedFiles = 1
HighSemantic Analysis Limited
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/index.jsView on unpkg •path = bin/index.js
kind = oversized_source_file
sizeBytes = 5058164
magicHex = [redacted]
MediumOversized Source File
Package contains source files above the normal full-analysis size ceiling.
bin/index.jsView on unpkg •path = bin/index.js
kind = oversized_cli_entrypoint
sizeBytes = 5058164
magicHex = [redacted]
MediumOversized Cli Entrypoint
Package contains an oversized executable-looking CLI entrypoint.
bin/index.jsView on unpkg