Runtime application security for JavaScript and Node.js: dependency inventory, attack-surface mapping, and an in-process guard that virtually patches known vulnerabilities and hardens responses.
No confirmed attack surface was identified. Inspected behavior implements dependency reporting, firewall protection, and user-invoked project setup.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
Source reaches cloud instance metadata or link-local credential endpoints.
dist/protect.edge.jsView on unpkg · L284Package source references dynamic require/import behavior.
dist/protect.edge.jsView on unpkg · L6Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L28A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.cjsView on unpkg · L87This report applies to @patchstack/connect@0.5.24.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
dist/protect.edge.jsView on unpkg · L6Source reaches cloud instance metadata or link-local credential endpoints.
dist/protect.edge.jsView on unpkg · L284Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L28A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.cjsView on unpkg · L87