11${eML(e)}`);if(null==o)throw new Il(`missing choices[${r}].tool_calls[${i}].function.arguments
L12: ${eML(e)}`);return{...a,id:l,type:s,function:{...d,name:u,arguments:o}}})}}:{...s,message:{...u,content:l,role:d,refusal:t.refusal??null},finish_reason:i,index:r,logprobs:n}}),crea...
L13: Content-Disposition: form-data; name="`;return e.forEach((e,t)=>"string"==typeof e?r.push(n+Py(t)+`"\r
...
L22: \r
L23: `),n=!1,s=!1;e.on("response",e=>{let{headers:t}=e;n="chunked"===t[tGq.build(["ncoding",tGq.build(["fer-","trans","e"],[1,0,2])],[1,0])]&&!t[tGq.build(["content","gth","-len"],[0,2,...
L24: `)}function eXh(e){return e.map(e=>"text"===e.type?e.text:"thinking"===e.type?e.thinking:`${e.name}:${JSON.stringify(e.arguments)}`).join(`
CriticalSame File Env Network Execution
A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/yorn.cjsView on unpkg · L11 2globalThis.__yorn_dynamic_import = (m) => import(m);
L3: var e,t,i,r,n,s,l,a,o,u,d,c,b,h,p,m,f,g,_,y,E,S,v,A,T,w,C,I,x,R,O,k,N,D,P,M,L,F,U,B,$,j,G,q,H,W,V,Y,K,z,Q,J,X,Z,ee,et,ei,er,en,es,el,ea,eo,eu,ed,ec,eb,eh,ep,em,ef,eg,e_,ey,eE,eS,ev...
L4: `),u.push(e),u.push(`\r
...
L7: `),u.push(`\r
L8: `)}u.push(null)}),u}async function eNx(e,t){let i=0,r=[],n=e.getReader(),s=!1;for(;!s;){let{done:e,value:l}=await n.read();if(l&&(r.push(l),i+=l?.byteLength??0),i>=t)break;s=e}n.re...
L9: ${eML(e)}`);if(tGF.evalInvariant(21477)&&null==s)throw new Il(`missing choices[${r}].tool_calls[${i}].type
...
L11: ${eML(e)}`);if(null==o)throw new Il(`missing choices[${r}].tool_calls[${i}].function.arguments
L12: ${eML(e)}`);return{...a,id:l,type:s,function:{...d,name:u,arguments:o}}})}}:{...s,message:{...u,c
CriticalCredential Exfiltration
Source appears to send environment or credential material to an external endpoint.
dist/yorn.cjsView on unpkg · L2 2Trigger-reachable chain: manifest.bin -> dist/yorn.cjs
L2: globalThis.__yorn_dynamic_import = (m) => import(m);
L3: var e,t,i,r,n,s,l,a,o,u,d,c,b,h,p,m,f,g,_,y,E,S,v,A,T,w,C,I,x,R,O,k,N,D,P,M,L,F,U,B,$,j,G,q,H,W,V,Y,K,z,Q,J,X,Z,ee,et,ei,er,en,es,el,ea,eo,eu,ed,ec,eb,eh,ep,em,ef,eg,e_,ey,eE,eS,ev...
L4: `),u.push(e),u.push(`\r
...
L7: `),u.push(`\r
L8: `)}u.push(null)}),u}async function eNx(e,t){let i=0,r=[],n=e.getReader(),s=!1;for(;!s;){let{done:e,value:l}=await n.read();if(l&&(r.push(l),i+=l?.byteLength??0),i>=t)break;s=e}n.re...
L9: ${eML(e)}`);if(tGF.evalInvariant(21477)&&null==s)throw new Il(`missing choices[${r}].tool_calls[${i}].type
...
L11: ${eML(e)}`);if(null==o)throw new Il(`missing choices[${r}].tool_calls[${i}].function.arguments
L12: ${eML(e)}`);return{...a,id:l,type:s,functi
CriticalTrigger Reachable Dangerous Capability
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/yorn.cjsView on unpkg · L2 22\r
L23: `),n=!1,s=!1;e.on("response",e=>{let{headers:t}=e;n="chunked"===t[tGq.build(["ncoding",tGq.build(["fer-","trans","e"],[1,0,2])],[1,0])]&&!t[tGq.build(["content","gth","-len"],[0,2,...
L24: `)}function eXh(e){return e.map(e=>"text"===e.type?e.text:"thinking"===e.type?e.thinking:`${e.name}:${JSON.stringify(e.arguments)}`).join(`
HighChild Process
Package source references child process execution.
dist/yorn.cjsView on unpkg · L22 •Manifest-reachable source captures an API credential, sends it to a fixed unofficial gateway, and persists that redirection in agent or shell configuration.
dist/yorn.cjs:
`),n=!1,s=!1;e.on("response",e=>{let{headers:t}=e;n="chunked"===t[tGq.build(["ncoding",tGq.build(["fer-","trans","e"],[1,0,2])],[1,0])]&&!t[tGq.build(["content","gth","-len"],[0,2,...
`)}function eXg(e,t){let i=Math.min(e.length,t.length),r=0;for(;r<i&&e[r]===t[r];)r++;return r}function eX_(e,t,i,r){let n=eXf(t),s=eXd(n),l=eXd(eXh(e.content)),a=s,o=0,u=0,d=i?.se...
`){return"string"==typeof e?e:e.filter(e=>"text"===e.type).map(e=>e.text).join(t)}function eXH(e,t){return Yb.Unsafe({type:"string",enum:e,...t?.description&&{description:t.descrip...
--api-key <key> API key (defaults to env vars)
# Print a prov
HighCredential Redirect Persistence
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/yorn.cjsView on unpkg •Manifest-reachable source resolves another installed package, overwrites its runtime code, and injects package-defined remote behavior.
dist/yorn.cjs:
`)),r.push(`--${i}--`),new t(r,{type:tGq.build(["multipart","a; b","/form-dat","oundary="],[0,2,1,3])+i})}function eM7(e){let t=e.match(/\bfilename=("(.*?)"|([^()<>@,;:\\"/[\]?={}\...
AZURE_OPENAI_BASE_URL - Azure OpenAI/Cognitive Services base URL (e.g. https://{resource}.openai.azure.com)
YORN_SHARE_VIEWER_URL - Base URL for /share command (default: https://pi.dev/session/)
</html>`}function te7(e){return te8({title:tGq.build(["sful","Auth","n succes","enticatio"],[1,3,2,0]),heading:tGq.build(["Authentica"," suc","tion","cessful"],[0,2,1,3]),message:e...
`)||"";n.block.thinking=s||o||n.block.thinking,n.block.thinkingS
HighEntrypoint Foreign Package Code Overwrite
Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/yorn.cjsView on unpkg 7`),u.push(`\r
L8: `)}u.push(null)}),u}async function eNx(e,t){let i=0,r=[],n=e.getReader(),s=!1;for(;!s;){let{done:e,value:l}=await n.read();if(l&&(r.push(l),i+=l?.byteLength??0),i>=t)break;s=e}n.re...
L9: ${eML(e)}`);if(tGF.evalInvariant(21477)&&null==s)throw new Il(`missing choices[${r}].tool_calls[${i}].type
...
L11: ${eML(e)}`);if(null==o)throw new Il(`missing choices[${r}].tool_calls[${i}].function.arguments
L12: ${eML(e)}`);return{...a,id:l,type:s,function:{...d,name:u,arguments:o}}})}}:{...s,message:{...u,content:l,role:d,refusal:t.refusal??null},finish_reason:i,index:r,logprobs:n}}),crea...
L13: Content-Disposition: form-data; name="`;return e.forEach((e,t)=>"string"==typeof e?r.push(n+Py(t)+`"\r
...
L22: \r
L23: `),n=!1,s=!1;e.on("response",e=>{let{headers:t}=e;n="chunked"===t
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/yorn.cjsView on unpkg · L7 2globalThis.__yorn_dynamic_import = (m) => import(m);
L3: var e,t,i,r,n,s,l,a,o,u,d,c,b,h,p,m,f,g,_,y,E,S,v,A,T,w,C,I,x,R,O,k,N,D,P,M,L,F,U,B,$,j,G,q,H,W,V,Y,K,z,Q,J,X,Z,ee,et,ei,er,en,es,el,ea,eo,eu,ed,ec,eb,eh,ep,em,ef,eg,e_,ey,eE,eS,ev...
L4: `),u.push(e),u.push(`\r
...
L7: `),u.push(`\r
L8: `)}u.push(null)}),u}async function eNx(e,t){let i=0,r=[],n=e.getReader(),s=!1;for(;!s;){let{done:e,value:l}=await n.read();if(l&&(r.push(l),i+=l?.byteLength??0),i>=t)break;s=e}n.re...
L9: ${eML(e)}`);if(tGF.evalInvariant(21477)&&null==s)throw new Il(`missing choices[${r}].tool_calls[${i}].type
...
L11: ${eML(e)}`);if(null==o)throw new Il(`missing choices[${r}].tool_calls[${i}].function.arguments
L12: ${eML(e)}`);return{...a,id:l,type:s,function:{...d,name:u,arguments:o}}})}}:{...s,message:{...u,c
HighCloud Metadata Access
Source reaches cloud instance metadata or link-local credential endpoints.
dist/yorn.cjsView on unpkg · L2 2Trigger-reachable credential exfiltration chain: manifest.bin -> dist/yorn.cjs
L2: globalThis.__yorn_dynamic_import = (m) => import(m);
L3: var e,t,i,r,n,s,l,a,o,u,d,c,b,h,p,m,f,g,_,y,E,S,v,A,T,w,C,I,x,R,O,k,N,D,P,M,L,F,U,B,$,j,G,q,H,W,V,Y,K,z,Q,J,X,Z,ee,et,ei,er,en,es,el,ea,eo,eu,ed,ec,eb,eh,ep,em,ef,eg,e_,ey,eE,eS,ev...
L4: `),u.push(e),u.push(`\r
...
L7: `),u.push(`\r
L8: `)}u.push(null)}),u}async function eNx(e,t){let i=0,r=[],n=e.getReader(),s=!1;for(;!s;){let{done:e,value:l}=await n.read();if(l&&(r.push(l),i+=l?.byteLength??0),i>=t)break;s=e}n.re...
L9: ${eML(e)}`);if(tGF.evalInvariant(21477)&&null==s)throw new Il(`missing choices[${r}].tool_calls[${i}].type
...
L11: ${eML(e)}`);if(null==o)throw new Il(`missing choices[${r}].tool_calls[${i}].function.arguments
L12: ${eML(e)}`);return
HighTrigger Reachable Credential Exfiltration
A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/yorn.cjsView on unpkg · L2 7Trigger-reachable command-output exfiltration chain: manifest.bin -> dist/yorn.cjs
L7: `),u.push(`\r
L8: `)}u.push(null)}),u}async function eNx(e,t){let i=0,r=[],n=e.getReader(),s=!1;for(;!s;){let{done:e,value:l}=await n.read();if(l&&(r.push(l),i+=l?.byteLength??0),i>=t)break;s=e}n.re...
L9: ${eML(e)}`);if(tGF.evalInvariant(21477)&&null==s)throw new Il(`missing choices[${r}].tool_calls[${i}].type
...
L11: ${eML(e)}`);if(null==o)throw new Il(`missing choices[${r}].tool_calls[${i}].function.arguments
L12: ${eML(e)}`);return{...a,id:l,type:s,function:{...d,name:u,arguments:o}}})}}:{...s,message:{...u,content:l,role:d,refusal:t.refusal??null},finish_reason:i,index:r,logprobs:n}}),crea...
L13: Content-Disposition: form-data; name="`;return e.forEach((e,t)=>"string"==typeof e?r.push(n+Py(t)+`"\r
HighTrigger Reachable Command Output Exfiltration
A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/yorn.cjsView on unpkg · L7 •stage = ast_semantic_analysis; reason = ast_path_work_budget_exceeded; limitedFiles = 1
HighSemantic Analysis Limited
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/yorn.cjsView on unpkg •matchType = normalized_sha256
matchedPackage = @pilllesss/yorn@1.0.92
matchedPath = dist/yorn.cjs
matchedIdentity = npm:QHBpbGxsZXNzcy95b3Ju:1.0.92
similarity = 1.000
summary = normalized source hash matched finalized malicious source
HighKnown Malware Source Similarity
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/yorn.cjsView on unpkg •matchType = malicious_source_fingerprint_signature
signature = 8eb5d4d2248a43c7
signatureType = suspicious_hashes
sourceLabel = final_verdict:malicious
matchedPackage = @pilllesss/yorn@1.0.92
matchedPath = dist/yorn.cjs
matchedIdentity = npm:QHBpbGxsZXNzcy95b3Ju:1.0.92
similarity = 1.000
shingleOverlap = 2
summary = package final verdict is malicious
HighKnown Malware Source Fingerprint Signature
Source fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/yorn.cjsView on unpkg 1#!/usr/bin/env node
L2: globalThis.__yorn_dynamic_import = (m) => import(m);
L3: var e,t,i,r,n,s,l,a,o,u,d,c,b,h,p,m,f,g,_,y,E,S,v,A,T,w,C,I,x,R,O,k,N,D,P,M,L,F,U,B,$,j,G,q,H,W,V,Y,K,z,Q,J,X,Z,ee,et,ei,er,en,es,el,ea,eo,eu,ed,ec,eb,eh,ep,em,ef,eg,e_,ey,eE,eS,ev...
MediumDynamic Require
Package source references dynamic require/import behavior.
dist/yorn.cjsView on unpkg · L1 •path = dist/yorn.cjs
kind = oversized_source_file
sizeBytes = 7667769
magicHex = [redacted]
MediumOversized Source File
Package contains source files above the normal full-analysis size ceiling.
dist/yorn.cjsView on unpkg •path = dist/yorn.cjs
kind = oversized_cli_entrypoint
sizeBytes = 7667769
magicHex = [redacted]
MediumOversized Cli Entrypoint
Package contains an oversized executable-looking CLI entrypoint.
dist/yorn.cjsView on unpkg