Runtime application security for JavaScript and Node.js: dependency inventory, attack-surface mapping, and an in-process guard that virtually patches known vulnerabilities and hardens responses.
No confirmed attack was identified. Inspected behavior supports dependency inventory reporting, configurable request protection, and explicit CLI setup.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
Source reaches cloud instance metadata or link-local credential endpoints.
dist/protect.edge.jsView on unpkg · L284Package source references dynamic require/import behavior.
dist/protect.edge.jsView on unpkg · L6Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L28A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.cjsView on unpkg · L87This report applies to @patchstack/connect@0.5.23.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/protect.edge.jsView on unpkg · L6Source reaches cloud instance metadata or link-local credential endpoints.
dist/protect.edge.jsView on unpkg · L284Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L28A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.cjsView on unpkg · L87