155`);return a!==-1&&(t=jKe(t,n,o,a)),o+t+n};Object.defineProperties(lk.prototype,KE);__n=lk(),cOi=lk({level:HKe?HKe.level:0}),$Ke=__n});function Uce(e,t,{ignoreNonConfigurable:r=!1}=...
L156: ${t}`,v_n=Object.getOwnPropertyDescriptor(Function.prototype,"toString"),I_n=Object.getOwnPropertyDescriptor(Function.prototype.toString,"name"),w_n=(e,t,r)=>{let o=r===""?"":`with...
L157: `||r==="\r"}#S(){this.#l||(this.#l=setTimeout(()=>{this.#l=void 0,this.isSpinning&&this.#y()},oAn),typeof this.#l?.unref=="function"&&this.#l.unref())}#b(){this.#l&&(clearTimeout(t...
...
L166: `;case"<i>":case"<em>":case"</i>":case"</em>":return"*";case"<b>":case"</b>":return"**";case"~!":case"!~":return"||";case"&":return"&";case"'":return"'";case"<":return"...
L167: `;return GW.default.writeFileS
CriticalRemote Asset Decode Execute
Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/cli.jsView on unpkg · L155 153Trigger-reachable chain: scripts.start -> dist/cli.js
L153: `)+r,n=o+1,o=e.indexOf(`
L154: `,n)}while(o!==-1);return a+=e.slice(n),a}var GKe=me(()=>{});function lk(e){return m_n(e)}var KKe,HKe,Lce,GE,ck,VKe,KE,b_n,m_n,qce,g_n,O_n,Bce,wW,M_n,__n,cOi,$Ke,JKe=me(()=>{LKe();...
L155: `);return a!==-1&&(t=jKe(t,n,o,a)),o+t+n};Object.defineProperties(lk.prototype,KE);__n=lk(),cOi=lk({level:HKe?HKe.level:0}),$Ke=__n});function Uce(e,t,{ignoreNonConfigurable:r=!1}=...
L156: ${t}`,v_n=Object.getOwnPropertyDescriptor(Function.prototype,"toString"),I_n=Object.getOwnPropertyDescriptor(Function.prototype.toString,"name"),w_n=(e,t,r)=>{let o=r===""?"":`with...
L157: `||r==="\r"}#S(){this.#l||(this.#l=setTimeout(()=>{this.#l=void 0,this.isSpinning&&this.#y()},oAn),typeof this.#l?.unref=="function"&&this.
CriticalTrigger Reachable Dangerous Capability
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkg · L153 166`;case"<i>":case"<em>":case"</i>":case"</em>":return"*";case"<b>":case"</b>":return"**";case"~!":case"!~":return"||";case"&":return"&";case"'":return"'";case"<":return"...
L167: `;return GW.default.writeFileSync(e,r,"utf8"),gt(`Created ${uue.default.basename(e)} in ${process.cwd()} (defaults).`,"info"),{config:t,configPath:e,exists:!0}}catch(t){let r=t&&t....
L168: \\[?(?:
155`);return a!==-1&&(t=jKe(t,n,o,a)),o+t+n};Object.defineProperties(lk.prototype,KE);__n=lk(),cOi=lk({level:HKe?HKe.level:0}),$Ke=__n});function Uce(e,t,{ignoreNonConfigurable:r=!1}=...
L156: ${t}`,v_n=Object.getOwnPropertyDescriptor(Function.prototype,"toString"),I_n=Object.getOwnPropertyDescriptor(Function.prototype.toString,"name"),w_n=(e,t,r)=>{let o=r===""?"":`with...
L157: `||r==="\r"}#S(){this.#l||(this.#l=setTimeout(()=>{this.#l=void 0,this.isSpinning&&this.#y()},oAn),typeof this.#l?.unref=="function"&&this.#l.unref())}#b(){this.#l&&(clearTimeout(t...
L158: `))o+=Math.max(1,Math.ceil(ile(n)/r));return o}get color(){return this.#f}set color(t){if(t!==void 0&&t!==!1&&!cAn.has(t))throw new Error("The `color` option must be a valid color ...
...
L166: `;case"<i>":case"<em>":case"</
HighSame File Env Network Execution
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli.jsView on unpkg · L155 •Manifest-reachable source captures an API credential, sends it to a fixed unofficial gateway, and persists that redirection in agent or shell configuration.
dist/cli.js:
`,r:"\r",t:" "},a,i=function(O){throw{name:"SyntaxError",message:O,at:r,text:a}},s=function(O){return O&&O!==o&&i("Expected '"+O+"' instead of '"+o+"'"),o=a.charAt(r),r+=1,o},c=fun...
`).map(t=>t.trim()).join(" ")};IPe.O=function(e){return this.inspectOpts.colors=this.useColors,uL.inspect(e,this.inspectOpts)}});var xn=L((dsi,_Y)=>{typeof process>"u"||process.typ...
`;if(o.username||o.password){let y=`${decodeURIComponent(o.username)}:${decodeURIComponent(o.password)}`;a["Proxy-Authorization"]=`Basic ${Buffer.from(y).toString("base64")}`}a.Hos...
`)}function JY(e){let t={interpolation:"rgb",hsvSpin:"short",...e};if(e!==void
HighCredential Redirect Persistence
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkg 153`)+r,n=o+1,o=e.indexOf(`
L154: `,n)}while(o!==-1);return a+=e.slice(n),a}var GKe=me(()=>{});function lk(e){return m_n(e)}var KKe,HKe,Lce,GE,ck,VKe,KE,b_n,m_n,qce,g_n,O_n,Bce,wW,M_n,__n,cOi,$Ke,JKe=me(()=>{LKe();...
L155: `);return a!==-1&&(t=jKe(t,n,o,a)),o+t+n};Object.defineProperties(lk.prototype,KE);__n=lk(),cOi=lk({level:HKe?HKe.level:0}),$Ke=__n});function Uce(e,t,{ignoreNonConfigurable:r=!1}=...
L156: ${t}`,v_n=Object.getOwnPropertyDescriptor(Function.prototype,"toString"),I_n=Object.getOwnPropertyDescriptor(Function.prototype.toString,"name"),w_n=(e,t,r)=>{let o=r===""?"":`with...
L157: `||r==="\r"}#S(){this.#l||(this.#l=setTimeout(()=>{this.#l=void 0,this.isSpinning&&this.#y()},oAn),typeof this.#l?.unref=="function"&&this.#l.unref())}#b(){this.#l&&(clearTimeout(t...
L158: `))
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/cli.jsView on unpkg · L153 1#!/usr/bin/env node
L2: "use strict";var HIt=Object.create;var C6=Object.defineProperty;var VIt=Object.getOwnPropertyDescriptor;var $It=Object.getOwnPropertyNames;var JIt=Object.getPrototypeOf,XIt=Object....
L3: \\[?(?:
...
L28: `;rr.DEFAULT_CONTENT_TYPE="application/octet-stream";rr.prototype.append=function(e,t,r){r=r||{},typeof r=="string"&&(r={filename:r});var o=KX.prototype.append.bind(this);if((typeo...
L29: `).some(o=>o.indexOf("(https.js:")!==-1||o.indexOf("node:https:")!==-1)}incrementSockets(t){if(this.maxSockets===1/0&&this.maxTotalSockets===1/0)return null;this.sockets[t]||(this....
L30: `).join(`
...
L32: `)}function dqt(e){e?process.env.DEBUG=e:delete process.env.DEBUG}function hqt(){return process.env.DEBUG}function yqt(e){e.inspectOpts={};let t=Object.keys(_s.inspectOpt
HighSandbox Evasion Gated Capability
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/cli.jsView on unpkg · L1 153Trigger-reachable command-output exfiltration chain: scripts.start -> dist/cli.js
L153: `)+r,n=o+1,o=e.indexOf(`
L154: `,n)}while(o!==-1);return a+=e.slice(n),a}var GKe=me(()=>{});function lk(e){return m_n(e)}var KKe,HKe,Lce,GE,ck,VKe,KE,b_n,m_n,qce,g_n,O_n,Bce,wW,M_n,__n,cOi,$Ke,JKe=me(()=>{LKe();...
L155: `);return a!==-1&&(t=jKe(t,n,o,a)),o+t+n};Object.defineProperties(lk.prototype,KE);__n=lk(),cOi=lk({level:HKe?HKe.level:0}),$Ke=__n});function Uce(e,t,{ignoreNonConfigurable:r=!1}=...
L156: ${t}`,v_n=Object.getOwnPropertyDescriptor(Function.prototype,"toString"),I_n=Object.getOwnPropertyDescriptor(Function.prototype.toString,"name"),w_n=(e,t,r)=>{let o=r===""?"":`with...
L157: `||r==="\r"}#S(){this.#l||(this.#l=setTimeout(()=>{this.#l=void 0,this.isSpinning&&this.#y()},oAn),typeof this.
HighTrigger Reachable Command Output Exfiltration
A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/cli.jsView on unpkg · L153 1Trigger-reachable persistence chain: scripts.start -> dist/cli.js
L1: #!/usr/bin/env node
L2: "use strict";var HIt=Object.create;var C6=Object.defineProperty;var VIt=Object.getOwnPropertyDescriptor;var $It=Object.getOwnPropertyNames;var JIt=Object.getPrototypeOf,XIt=Object....
L3: \\[?(?:
...
L28: `;rr.DEFAULT_CONTENT_TYPE="application/octet-stream";rr.prototype.append=function(e,t,r){r=r||{},typeof r=="string"&&(r={filename:r});var o=KX.prototype.append.bind(this);if((typeo...
L29: `).some(o=>o.indexOf("(https.js:")!==-1||o.indexOf("node:https:")!==-1)}incrementSockets(t){if(this.maxSockets===1/0&&this.maxTotalSockets===1/0)return null;this.sockets[t]||(this....
L30: `).join(`
...
L32: `)}function dqt(e){e?process.env.DEBUG=e:delete process.env.DEBUG}function hqt(){return process.env.DEBU
HighTrigger Reachable Persistence
A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/cli.jsView on unpkg · L1 196${r}
L197: ${G9(t)}</${e.tag}>`:"/>";return o+n}var hft,Yn,ov,et,ep,ri,lde,tp,ude,G9,pde=me(()=>{hft=ke(sc(),1);ao();cde();Yn=(e,t)=>Array.isArray(e?.content)?e.content.filter(r=>r.tag===t):[...
L198: `))}});var Idt=L((ihr,vdt)=>{var iNn=require("node:util"),Ade=require("node:stream"),rNn=_h();GC();var oNn=iNn.debuglog("sharp"),aNn=e=>{pA.queue.emit("change",e)},pA=function(e,t)...
HighRuntime Package Install
Package source invokes a package manager install command at runtime.
dist/cli.jsView on unpkg · L196 •stage = ast_semantic_analysis; reason = ast_path_work_budget_exceeded; limitedFiles = 2
HighSemantic Analysis Limited
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/cli.jsView on unpkg 1#!/usr/bin/env node
L2: "use strict";var HIt=Object.create;var C6=Object.defineProperty;var VIt=Object.getOwnPropertyDescriptor;var $It=Object.getOwnPropertyNames;var JIt=Object.getPrototypeOf,XIt=Object....
L3: \\[?(?:
...
L28: `;rr.DEFAULT_CONTENT_TYPE="application/octet-stream";rr.prototype.append=function(e,t,r){r=r||{},typeof r=="string"&&(r={filename:r});var o=KX.prototype.append.bind(this);if((typeo...
L29: `).some(o=>o.indexOf("(https.js:")!==-1||o.indexOf("node:https:")!==-1)}incrementSockets(t){if(this.maxSockets===1/0&&this.maxTotalSockets===1/0)return null;this.sockets[t]||(this....
L30: `).join(`
...
L32: `)}function dqt(e){e?process.env.DEBUG=e:delete process.env.DEBUG}function hqt(){return process.env.DEBUG}function yqt(e){e.inspectOpts={};let t=Object.keys(_s.inspectOpt
MediumInstall Persistence
Source writes installer persistence such as shell profile or service configuration.
dist/cli.jsView on unpkg · L1 •path = dist/cli.js
kind = oversized_source_file
sizeBytes = 8011700
magicHex = [redacted]
MediumOversized Source File
Package contains source files above the normal full-analysis size ceiling.
dist/cli.jsView on unpkg •path = dist/cli.js
kind = oversized_cli_entrypoint
sizeBytes = 8011700
magicHex = [redacted]
MediumOversized Cli Entrypoint
Package contains an oversized executable-looking CLI entrypoint.
dist/cli.jsView on unpkg 1#!/usr/bin/env node
L2: "use strict";var HIt=Object.create;var C6=Object.defineProperty;var VIt=Object.getOwnPropertyDescriptor;var $It=Object.getOwnPropertyNames;var JIt=Object.getPrototypeOf,XIt=Object....
L3: \\[?(?:
...
L28: `;rr.DEFAULT_CONTENT_TYPE="application/octet-stream";rr.prototype.append=function(e,t,r){r=r||{},typeof r=="string"&&(r={filename:r});var o=KX.prototype.append.bind(this);if((typeo...
L29: `).some(o=>o.indexOf("(https.js:")!==-1||o.indexOf("node:https:")!==-1)}incrementSockets(t){if(this.maxSockets===1/0&&this.maxTotalSockets===1/0)return null;this.sockets[t]||(this....
L30: `).join(`
...
L32: `)}function dqt(e){e?process.env.DEBUG=e:delete process.env.DEBUG}function hqt(){return process.env.DEBUG}function yqt(e){e.inspectOpts={};let t=Object.keys(_s.inspectOpt
LowWeak Crypto
Package source references weak cryptographic algorithms.
dist/cli.jsView on unpkg · L1