155`);return a!==-1&&(t=GKe(t,n,o,a)),o+t+n};Object.defineProperties(lk.prototype,KE);E_n=lk(),pOi=lk({level:VKe?VKe.level:0}),JKe=E_n});function Wce(e,t,{ignoreNonConfigurable:r=!1}=...
L156: ${t}`,P_n=Object.getOwnPropertyDescriptor(Function.prototype,"toString"),z_n=Object.getOwnPropertyDescriptor(Function.prototype.toString,"name"),R_n=(e,t,r)=>{let o=r===""?"":`with...
L157: `||r==="\r"}#S(){this.#l||(this.#l=setTimeout(()=>{this.#l=void 0,this.isSpinning&&this.#y()},cAn),typeof this.#l?.unref=="function"&&this.#l.unref())}#b(){this.#l&&(clearTimeout(t...
...
L166: `;case"<i>":case"<em>":case"</i>":case"</em>":return"*";case"<b>":case"</b>":return"**";case"~!":case"!~":return"||";case"&":return"&";case"'":return"'";case"<":return"...
L167: `;return GW.default.writeFileS
CriticalRemote Asset Decode Execute
Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/cli.jsView on unpkg · L155 153Trigger-reachable chain: scripts.start -> dist/cli.js
L153: `)+r,n=o+1,o=e.indexOf(`
L154: `,n)}while(o!==-1);return a+=e.slice(n),a}var KKe=me(()=>{});function lk(e){return M_n(e)}var HKe,VKe,qce,GE,ck,$Ke,KE,O_n,M_n,Bce,__n,A_n,Uce,wW,S_n,E_n,pOi,JKe,XKe=me(()=>{qKe();...
L155: `);return a!==-1&&(t=GKe(t,n,o,a)),o+t+n};Object.defineProperties(lk.prototype,KE);E_n=lk(),pOi=lk({level:VKe?VKe.level:0}),JKe=E_n});function Wce(e,t,{ignoreNonConfigurable:r=!1}=...
L156: ${t}`,P_n=Object.getOwnPropertyDescriptor(Function.prototype,"toString"),z_n=Object.getOwnPropertyDescriptor(Function.prototype.toString,"name"),R_n=(e,t,r)=>{let o=r===""?"":`with...
L157: `||r==="\r"}#S(){this.#l||(this.#l=setTimeout(()=>{this.#l=void 0,this.isSpinning&&this.#y()},cAn),typeof this.#l?.unref=="function"&&this.
CriticalTrigger Reachable Dangerous Capability
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkg · L153 166`;case"<i>":case"<em>":case"</i>":case"</em>":return"*";case"<b>":case"</b>":return"**";case"~!":case"!~":return"||";case"&":return"&";case"'":return"'";case"<":return"...
L167: `;return GW.default.writeFileSync(e,r,"utf8"),gt(`Created ${pue.default.basename(e)} in ${process.cwd()} (defaults).`,"info"),{config:t,configPath:e,exists:!0}}catch(t){let r=t&&t....
L168: \\[?(?:
155`);return a!==-1&&(t=GKe(t,n,o,a)),o+t+n};Object.defineProperties(lk.prototype,KE);E_n=lk(),pOi=lk({level:VKe?VKe.level:0}),JKe=E_n});function Wce(e,t,{ignoreNonConfigurable:r=!1}=...
L156: ${t}`,P_n=Object.getOwnPropertyDescriptor(Function.prototype,"toString"),z_n=Object.getOwnPropertyDescriptor(Function.prototype.toString,"name"),R_n=(e,t,r)=>{let o=r===""?"":`with...
L157: `||r==="\r"}#S(){this.#l||(this.#l=setTimeout(()=>{this.#l=void 0,this.isSpinning&&this.#y()},cAn),typeof this.#l?.unref=="function"&&this.#l.unref())}#b(){this.#l&&(clearTimeout(t...
L158: `))o+=Math.max(1,Math.ceil(rle(n)/r));return o}get color(){return this.#f}set color(t){if(t!==void 0&&t!==!1&&!pAn.has(t))throw new Error("The `color` option must be a valid color ...
...
L166: `;case"<i>":case"<em>":case"</
HighSame File Env Network Execution
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli.jsView on unpkg · L155 •Manifest-reachable source captures an API credential, sends it to a fixed unofficial gateway, and persists that redirection in agent or shell configuration.
dist/cli.js:
`,r:"\r",t:" "},a,i=function(O){throw{name:"SyntaxError",message:O,at:r,text:a}},s=function(O){return O&&O!==o&&i("Expected '"+O+"' instead of '"+o+"'"),o=a.charAt(r),r+=1,o},c=fun...
`).map(t=>t.trim()).join(" ")};wPe.O=function(e){return this.inspectOpts.colors=this.useColors,uL.inspect(e,this.inspectOpts)}});var xn=L((bsi,AY)=>{typeof process>"u"||process.typ...
`;if(o.username||o.password){let y=`${decodeURIComponent(o.username)}:${decodeURIComponent(o.password)}`;a["Proxy-Authorization"]=`Basic ${Buffer.from(y).toString("base64")}`}a.Hos...
`)}function XY(e){let t={interpolation:"rgb",hsvSpin:"short",...e};if(e!==void
HighCredential Redirect Persistence
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.jsView on unpkg 153`)+r,n=o+1,o=e.indexOf(`
L154: `,n)}while(o!==-1);return a+=e.slice(n),a}var KKe=me(()=>{});function lk(e){return M_n(e)}var HKe,VKe,qce,GE,ck,$Ke,KE,O_n,M_n,Bce,__n,A_n,Uce,wW,S_n,E_n,pOi,JKe,XKe=me(()=>{qKe();...
L155: `);return a!==-1&&(t=GKe(t,n,o,a)),o+t+n};Object.defineProperties(lk.prototype,KE);E_n=lk(),pOi=lk({level:VKe?VKe.level:0}),JKe=E_n});function Wce(e,t,{ignoreNonConfigurable:r=!1}=...
L156: ${t}`,P_n=Object.getOwnPropertyDescriptor(Function.prototype,"toString"),z_n=Object.getOwnPropertyDescriptor(Function.prototype.toString,"name"),R_n=(e,t,r)=>{let o=r===""?"":`with...
L157: `||r==="\r"}#S(){this.#l||(this.#l=setTimeout(()=>{this.#l=void 0,this.isSpinning&&this.#y()},cAn),typeof this.#l?.unref=="function"&&this.#l.unref())}#b(){this.#l&&(clearTimeout(t...
L158: `))
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/cli.jsView on unpkg · L153 1#!/usr/bin/env node
L2: "use strict";var JIt=Object.create;var C6=Object.defineProperty;var XIt=Object.getOwnPropertyDescriptor;var YIt=Object.getOwnPropertyNames;var QIt=Object.getPrototypeOf,ZIt=Object....
L3: \\[?(?:
...
L28: `;rr.DEFAULT_CONTENT_TYPE="application/octet-stream";rr.prototype.append=function(e,t,r){r=r||{},typeof r=="string"&&(r={filename:r});var o=HX.prototype.append.bind(this);if((typeo...
L29: `).some(o=>o.indexOf("(https.js:")!==-1||o.indexOf("node:https:")!==-1)}incrementSockets(t){if(this.maxSockets===1/0&&this.maxTotalSockets===1/0)return null;this.sockets[t]||(this....
L30: `).join(`
...
L32: `)}function bqt(e){e?process.env.DEBUG=e:delete process.env.DEBUG}function mqt(){return process.env.DEBUG}function gqt(e){e.inspectOpts={};let t=Object.keys(_s.inspectOpt
HighSandbox Evasion Gated Capability
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/cli.jsView on unpkg · L1 153Trigger-reachable command-output exfiltration chain: scripts.start -> dist/cli.js
L153: `)+r,n=o+1,o=e.indexOf(`
L154: `,n)}while(o!==-1);return a+=e.slice(n),a}var KKe=me(()=>{});function lk(e){return M_n(e)}var HKe,VKe,qce,GE,ck,$Ke,KE,O_n,M_n,Bce,__n,A_n,Uce,wW,S_n,E_n,pOi,JKe,XKe=me(()=>{qKe();...
L155: `);return a!==-1&&(t=GKe(t,n,o,a)),o+t+n};Object.defineProperties(lk.prototype,KE);E_n=lk(),pOi=lk({level:VKe?VKe.level:0}),JKe=E_n});function Wce(e,t,{ignoreNonConfigurable:r=!1}=...
L156: ${t}`,P_n=Object.getOwnPropertyDescriptor(Function.prototype,"toString"),z_n=Object.getOwnPropertyDescriptor(Function.prototype.toString,"name"),R_n=(e,t,r)=>{let o=r===""?"":`with...
L157: `||r==="\r"}#S(){this.#l||(this.#l=setTimeout(()=>{this.#l=void 0,this.isSpinning&&this.#y()},cAn),typeof this.
HighTrigger Reachable Command Output Exfiltration
A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/cli.jsView on unpkg · L153 1Trigger-reachable persistence chain: scripts.start -> dist/cli.js
L1: #!/usr/bin/env node
L2: "use strict";var JIt=Object.create;var C6=Object.defineProperty;var XIt=Object.getOwnPropertyDescriptor;var YIt=Object.getOwnPropertyNames;var QIt=Object.getPrototypeOf,ZIt=Object....
L3: \\[?(?:
...
L28: `;rr.DEFAULT_CONTENT_TYPE="application/octet-stream";rr.prototype.append=function(e,t,r){r=r||{},typeof r=="string"&&(r={filename:r});var o=HX.prototype.append.bind(this);if((typeo...
L29: `).some(o=>o.indexOf("(https.js:")!==-1||o.indexOf("node:https:")!==-1)}incrementSockets(t){if(this.maxSockets===1/0&&this.maxTotalSockets===1/0)return null;this.sockets[t]||(this....
L30: `).join(`
...
L32: `)}function bqt(e){e?process.env.DEBUG=e:delete process.env.DEBUG}function mqt(){return process.env.DEBU
HighTrigger Reachable Persistence
A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/cli.jsView on unpkg · L1 196${r}
L197: ${G9(t)}</${e.tag}>`:"/>";return o+n}var yft,Yn,ov,et,ep,ri,ude,tp,pde,G9,fde=me(()=>{yft=ke(cc(),1);ao();lde();Yn=(e,t)=>Array.isArray(e?.content)?e.content.filter(r=>r.tag===t):[...
L198: `))}});var wdt=L((ahr,Idt)=>{var aNn=require("node:util"),Sde=require("node:stream"),sNn=Sh();GC();var cNn=aNn.debuglog("sharp"),lNn=e=>{pA.queue.emit("change",e)},pA=function(e,t)...
HighRuntime Package Install
Package source invokes a package manager install command at runtime.
dist/cli.jsView on unpkg · L196 •stage = ast_semantic_analysis; reason = ast_path_work_budget_exceeded; limitedFiles = 2
HighSemantic Analysis Limited
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/cli.jsView on unpkg 1#!/usr/bin/env node
L2: "use strict";var JIt=Object.create;var C6=Object.defineProperty;var XIt=Object.getOwnPropertyDescriptor;var YIt=Object.getOwnPropertyNames;var QIt=Object.getPrototypeOf,ZIt=Object....
L3: \\[?(?:
...
L28: `;rr.DEFAULT_CONTENT_TYPE="application/octet-stream";rr.prototype.append=function(e,t,r){r=r||{},typeof r=="string"&&(r={filename:r});var o=HX.prototype.append.bind(this);if((typeo...
L29: `).some(o=>o.indexOf("(https.js:")!==-1||o.indexOf("node:https:")!==-1)}incrementSockets(t){if(this.maxSockets===1/0&&this.maxTotalSockets===1/0)return null;this.sockets[t]||(this....
L30: `).join(`
...
L32: `)}function bqt(e){e?process.env.DEBUG=e:delete process.env.DEBUG}function mqt(){return process.env.DEBUG}function gqt(e){e.inspectOpts={};let t=Object.keys(_s.inspectOpt
MediumInstall Persistence
Source writes installer persistence such as shell profile or service configuration.
dist/cli.jsView on unpkg · L1 •path = dist/cli.js
kind = oversized_source_file
sizeBytes = 8026370
magicHex = [redacted]
MediumOversized Source File
Package contains source files above the normal full-analysis size ceiling.
dist/cli.jsView on unpkg •path = dist/cli.js
kind = oversized_cli_entrypoint
sizeBytes = 8026370
magicHex = [redacted]
MediumOversized Cli Entrypoint
Package contains an oversized executable-looking CLI entrypoint.
dist/cli.jsView on unpkg 1#!/usr/bin/env node
L2: "use strict";var JIt=Object.create;var C6=Object.defineProperty;var XIt=Object.getOwnPropertyDescriptor;var YIt=Object.getOwnPropertyNames;var QIt=Object.getPrototypeOf,ZIt=Object....
L3: \\[?(?:
...
L28: `;rr.DEFAULT_CONTENT_TYPE="application/octet-stream";rr.prototype.append=function(e,t,r){r=r||{},typeof r=="string"&&(r={filename:r});var o=HX.prototype.append.bind(this);if((typeo...
L29: `).some(o=>o.indexOf("(https.js:")!==-1||o.indexOf("node:https:")!==-1)}incrementSockets(t){if(this.maxSockets===1/0&&this.maxTotalSockets===1/0)return null;this.sockets[t]||(this....
L30: `).join(`
...
L32: `)}function bqt(e){e?process.env.DEBUG=e:delete process.env.DEBUG}function mqt(){return process.env.DEBUG}function gqt(e){e.inspectOpts={};let t=Object.keys(_s.inspectOpt
LowWeak Crypto
Package source references weak cryptographic algorithms.
dist/cli.jsView on unpkg · L1