Nimbus runtime package for Cloudflare Workers, re-exported publicly through @nimbus-sh/sdk/worker.
No confirmed attack surface was identified in the inspected code. Runtime process spawning and dynamic worker loading are product capabilities rather than install-time behavior.
Package source references child process execution.
dist/facets/process.js#virtual:normalized:round1View on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/facets/process.js#virtual:normalized:round1View on unpkgSource fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
public/_assets/real-vite-bundle.jsView on unpkg · L200Source passes code obtained from a remote response into a dynamic execution sink.
public/_assets/real-vite-bundle.jsView on unpkgPackage source references shell execution.
public/_assets/real-vite-bundle.jsView on unpkg · L69352Source contains an obfuscated payload loader that reconstructs and executes hidden code.
public/_assets/real-vite-bundle.jsView on unpkg · L22909Source file is highly similar to a previously finalized malicious package; route for source-aware review.
public/_assets/real-vite-bundle.jsView on unpkgPackage source references weak cryptographic algorithms.
public/_assets/real-vite-bundle.jsView on unpkg · L200Package source references dynamic code evaluation.
dist/facets/real-vite-fs-shim.js#virtual:normalized:round1View on unpkg · L780Package source references dynamic require/import behavior.
dist/facets/wasm-swap-registry.js#virtual:normalized:round1View on unpkg · L6Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/facets/manager.jsView on unpkg · L6Package source invokes a package manager install command at runtime.
scripts/bundle-real-vite.mjsView on unpkg · L377Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bundle-real-vite.mjsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
public/_assets/opencode/1.16.2/index-attach.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bundle-plugin-react.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bundle-npm-cjs.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/facets/real-vite-fs-shim.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runtime/node-shims.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
public/_assets/opencode/1.16.2/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/opentui/build-wasm.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/patch-install-deps.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/router/remote-api.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/session/routes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/wrangler/nimbus-wrangler.jsView on unpkgThis report applies to @nimbus-sh/worker@0.9.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
dist/facets/process.js#virtual:normalized:round1View on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/facets/process.js#virtual:normalized:round1View on unpkgSource fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
public/_assets/real-vite-bundle.jsView on unpkg · L200Source passes code obtained from a remote response into a dynamic execution sink.
public/_assets/real-vite-bundle.jsView on unpkgPackage source references shell execution.
public/_assets/real-vite-bundle.jsView on unpkg · L69352Source contains an obfuscated payload loader that reconstructs and executes hidden code.
public/_assets/real-vite-bundle.jsView on unpkg · L22909Source file is highly similar to a previously finalized malicious package; route for source-aware review.
public/_assets/real-vite-bundle.jsView on unpkgPackage source references weak cryptographic algorithms.
public/_assets/real-vite-bundle.jsView on unpkg · L200Package source references dynamic code evaluation.
dist/facets/real-vite-fs-shim.js#virtual:normalized:round1View on unpkg · L780Package source references dynamic require/import behavior.
dist/facets/wasm-swap-registry.js#virtual:normalized:round1View on unpkg · L6Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/facets/manager.jsView on unpkg · L6Package source invokes a package manager install command at runtime.
scripts/bundle-real-vite.mjsView on unpkg · L377Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bundle-real-vite.mjsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
public/_assets/opencode/1.16.2/index-attach.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bundle-plugin-react.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bundle-npm-cjs.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/facets/real-vite-fs-shim.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runtime/node-shims.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
public/_assets/opencode/1.16.2/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/opentui/build-wasm.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/patch-install-deps.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/router/remote-api.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/session/routes.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/wrangler/nimbus-wrangler.jsView on unpkg