Runtime application security for JavaScript and Node.js: dependency inventory, attack-surface mapping, and an in-process guard that virtually patches known vulnerabilities and hardens responses.
No confirmed attack surface was identified. Inspected behavior implements dependency reporting, service authentication, and runtime security verification.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
Package source references child process execution.
dist/protect/runtime/report-listeners.cjsView on unpkg · L34Source reaches cloud instance metadata or link-local credential endpoints.
dist/protect.edge.jsView on unpkg · L284Package source references dynamic require/import behavior.
dist/protect.edge.jsView on unpkg · L6Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L28Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.jsView on unpkg · L58A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.cjsView on unpkg · L87This report applies to @patchstack/connect@0.5.30.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
dist/protect/runtime/report-listeners.cjsView on unpkg · L34Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.jsView on unpkg · L58Package source references dynamic require/import behavior.
dist/protect.edge.jsView on unpkg · L6Source reaches cloud instance metadata or link-local credential endpoints.
dist/protect.edge.jsView on unpkg · L284Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L28A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.cjsView on unpkg · L87