Runtime application security for JavaScript and Node.js: dependency inventory, attack-surface mapping, and an in-process guard that virtually patches known vulnerabilities and hardens responses.
A package-supplied prompt can cause an AI assistant to run setup, which modifies a consumer project and establishes recurring install and build hooks. The hooks report dependency inventories to Patchstack and can add runtime protection and a disclosure widget.
Source reaches cloud instance metadata or link-local credential endpoints.
dist/protect.edge.jsView on unpkg · L275Package source references dynamic require/import behavior.
dist/protect.edge.jsView on unpkg · L6Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L22A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.cjsView on unpkg · L81This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.jsView on unpkgThis report applies to @patchstack/connect@0.4.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/protect.edge.jsView on unpkg · L6This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.jsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/protect.edge.jsView on unpkg · L275Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L22A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.cjsView on unpkg · L81