Patchstack connector for JavaScript applications. Scans your lockfile and reports installed packages to Patchstack for vulnerability monitoring.
Static analysis flagged 12 finding(s) at 93.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Source reaches cloud instance metadata or link-local credential endpoints.
dist/protect.edge.jsView on unpkg · L57Package source references dynamic require/import behavior.
dist/protect.edge.jsView on unpkg · L6Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/index.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/protect.cjsView on unpkgThis report applies to @patchstack/connect@0.3.24.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/protect.edge.jsView on unpkg · L6Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/index.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/protect.cjsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/protect.edge.jsView on unpkg · L57