41`),b=y.shift();if(!b)return e.destroy(),r(new Error("No header received from proxy CONNECT response"));let w=b.split(" "),k=+w[1],g=w.slice(2).join(" "),v={};for(let x of y){if(!x)...
L42: `;if(n.username||n.password){let f=`${decodeURIComponent(n.username)}:${decodeURIComponent(n.password)}`;a["Proxy-Authorization"]=`Basic ${Buffer.from(f).toString("base64")}`}a.Hos...
L43: `;let c=(0,PM.parseProxyResponse)(i);i.write(`${s}\r
...
L56: \r
L57: `),n=!1,i=!1,a;e.on("response",o=>{let{headers:s}=o;n=s["transfer-encoding"]==="chunked"&&!s["content-length"]}),e.on("socket",o=>{let s=()=>{if(n&&!i){let l=new Error("Premature c...
L58: ==================================================================`),console.log("\u{1F510} ZPLUS WORKER TERMINAL LOGIN (HEADLESS LINUX / VPS)"),console.log("
CriticalRemote Asset Decode Execute
Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/cli.jsView on unpkg · L41 1Trigger-reachable chain: scripts.start -> dist/cli.js
L1: #!/usr/bin/env node
L2: "use strict";var TO=Object.create;var vd=Object.defineProperty;var RO=Object.getOwnPropertyDescriptor;var IO=Object.getOwnPropertyNames;var PO=Object.getPrototypeOf,OO=Object.proto...
L3: `)}};xa.DataSanitizer=wd});var wg=B(va=>{"use strict";Object.defineProperty(va,"__esModule",{value:!0});va.ConsoleLogger=void 0;va.createLogger=LO;va.formatActionableError=NO;var k...
L4: \\[?(?:
...
L21: `+w+"}":"{"+k.join(",")+"}",n=w,y}}typeof mb.stringify!="function"&&(mb.stringify=function(l,u,d){var f;if(n="",i="",typeof d=="number")for(f=0;f<d;f+=1)i+=" ";else typeof d=="stri...
L22: `,r:"\r",t:" "},a,o=function(w){throw{name:"SyntaxError",message:w,at:r,text:a}},s=function(w){return w&&w!==n&&o("Expected '"+w+"' inst
CriticalTrigger Reachable Dangerous Capability
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkg · L1 •matchType = previous_version_dangerous_delta
matchedPackage = @softtynet/zplus-worker@1.0.40
matchedIdentity = npm:QHNvZnR0eW5ldC96cGx1cy13b3JrZXI:1.0.40
similarity = 0.500
summary = stored previous version shares package body but lacks this dangerous source file
CriticalPrevious Version Dangerous Delta
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.jsView on unpkg 56\r
L57: `),n=!1,i=!1,a;e.on("response",o=>{let{headers:s}=o;n=s["transfer-encoding"]==="chunked"&&!s["content-length"]}),e.on("socket",o=>{let s=()=>{if(n&&!i){let l=new Error("Premature c...
L58: ==================================================================`),console.log("\u{1F510} ZPLUS WORKER TERMINAL LOGIN (HEADLESS LINUX / VPS)"),console.log("======================...
76[Windows.UI.Notifications.ToastNotificationManager]::CreateToastNotifier('ZPlus Worker').Show($toast);
L77: `;return(0,Tp.spawn)("powershell",["-Command",u],{detached:!0,stdio:"ignore"}).unref(),!0}}}catch{}return!1}};var Ip=class{constructor(t,r,n){this.config=t;this.engine=r;this.logge...
L78: `)[0].trim();i&&(r=i)}catch{r=Pt.default.resolve(process.cwd(),"dist/cli.js")}return{nodePath:t,cliPath:r}}getStatus(){let t=process.platform;if(t==="linux"){let r=Pt.default.join(...
54`)).replace(/\n/g,"%0A").replace(/\r/g,"%0D").replace(/"/g,"%22"),ea=(e,t,r)=>{if(t.length<r)throw new TypeError(`Failed to execute '${e}' on 'FormData': ${r} arguments required, b...
L55: --`+t;let r=new Uint8Array(t.length);for(let n=0;n<t.length;n++)r[n]=t.charCodeAt(n),this.boundaryChars[r[n]]=!0;this.boundary=r,this.lookbehind=new Uint8Array(this.boundary.length...
L56: \r
L57: `),n=!1,i=!1,a;e.on("response",o=>{let{headers:s}=o;n=s["transfer-encoding"]==="chunked"&&!s["content-length"]}),e.on("socket",o=>{let s=()=>{if(n&&!i){let l=new Error("Premature c...
L58: ==================================================================`),console.log("\u{1F510} ZPLUS WORKER TERMINAL LOGIN (HEADLESS LINUX / VPS)"),console.log("======================...
HighSame File Env Network Execution
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli.jsView on unpkg · L54 1#!/usr/bin/env node
L2: "use strict";var TO=Object.create;var vd=Object.defineProperty;var RO=Object.getOwnPropertyDescriptor;var IO=Object.getOwnPropertyNames;var PO=Object.getPrototypeOf,OO=Object.proto...
L3: `)}};xa.DataSanitizer=wd});var wg=B(va=>{"use strict";Object.defineProperty(va,"__esModule",{value:!0});va.ConsoleLogger=void 0;va.createLogger=LO;va.formatActionableError=NO;var k...
L4: \\[?(?:
...
L21: `+w+"}":"{"+k.join(",")+"}",n=w,y}}typeof mb.stringify!="function"&&(mb.stringify=function(l,u,d){var f;if(n="",i="",typeof d=="number")for(f=0;f<d;f+=1)i+=" ";else typeof d=="stri...
L22: `,r:"\r",t:" "},a,o=function(w){throw{name:"SyntaxError",message:w,at:r,text:a}},s=function(w){return w&&w!==n&&o("Expected '"+w+"' instead of '"+n+"'"),n=a.charAt(r),r+=1,n},c=fun...
L23: R
HighCredential Exfiltration
Source combines credential-like environment material and outbound requests; review data flow before blocking.
dist/cli.jsView on unpkg · L1 42`;if(n.username||n.password){let f=`${decodeURIComponent(n.username)}:${decodeURIComponent(n.password)}`;a["Proxy-Authorization"]=`Basic ${Buffer.from(f).toString("base64")}`}a.Hos...
L43: `;let c=(0,PM.parseProxyResponse)(i);i.write(`${s}\r
L44: `);let{connect:l,buffered:u}=await c;if(t.emit("proxyConnect",l),this.emit("proxyConnect",l,t),l.statusCode===200)return t.once("socket",OM),r.secureEndpoint?(Ps("Upgrading socket ...
...
L54: `)).replace(/\n/g,"%0A").replace(/\r/g,"%0D").replace(/"/g,"%22"),ea=(e,t,r)=>{if(t.length<r)throw new TypeError(`Failed to execute '${e}' on 'FormData': ${r} arguments required, b...
L55: --`+t;let r=new Uint8Array(t.length);for(let n=0;n<t.length;n++)r[n]=t.charCodeAt(n),this.boundaryChars[r[n]]=!0;this.boundary=r,this.lookbehind=new Uint8Array(this.b
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/cli.jsView on unpkg · L42 1#!/usr/bin/env node
L2: "use strict";var TO=Object.create;var vd=Object.defineProperty;var RO=Object.getOwnPropertyDescriptor;var IO=Object.getOwnPropertyNames;var PO=Object.getPrototypeOf,OO=Object.proto...
L3: `)}};xa.DataSanitizer=wd});var wg=B(va=>{"use strict";Object.defineProperty(va,"__esModule",{value:!0});va.ConsoleLogger=void 0;va.createLogger=LO;va.formatActionableError=NO;var k...
L4: \\[?(?:
...
L21: `+w+"}":"{"+k.join(",")+"}",n=w,y}}typeof mb.stringify!="function"&&(mb.stringify=function(l,u,d){var f;if(n="",i="",typeof d=="number")for(f=0;f<d;f+=1)i+=" ";else typeof d=="stri...
L22: `,r:"\r",t:" "},a,o=function(w){throw{name:"SyntaxError",message:w,at:r,text:a}},s=function(w){return w&&w!==n&&o("Expected '"+w+"' instead of '"+n+"'"),n=a.charAt(r),r+=1,n},c=fun...
L23: R
HighSandbox Evasion Gated Capability
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/cli.jsView on unpkg · L1 1Trigger-reachable credential exfiltration chain: scripts.start -> dist/cli.js
L1: #!/usr/bin/env node
L2: "use strict";var TO=Object.create;var vd=Object.defineProperty;var RO=Object.getOwnPropertyDescriptor;var IO=Object.getOwnPropertyNames;var PO=Object.getPrototypeOf,OO=Object.proto...
L3: `)}};xa.DataSanitizer=wd});var wg=B(va=>{"use strict";Object.defineProperty(va,"__esModule",{value:!0});va.ConsoleLogger=void 0;va.createLogger=LO;va.formatActionableError=NO;var k...
L4: \\[?(?:
...
L21: `+w+"}":"{"+k.join(",")+"}",n=w,y}}typeof mb.stringify!="function"&&(mb.stringify=function(l,u,d){var f;if(n="",i="",typeof d=="number")for(f=0;f<d;f+=1)i+=" ";else typeof d=="stri...
L22: `,r:"\r",t:" "},a,o=function(w){throw{name:"SyntaxError",message:w,at:r,text:a}},s=function(w){return w&&w!==n&&
HighTrigger Reachable Credential Exfiltration
A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.jsView on unpkg · L1 42Trigger-reachable command-output exfiltration chain: scripts.start -> dist/cli.js
L42: `;if(n.username||n.password){let f=`${decodeURIComponent(n.username)}:${decodeURIComponent(n.password)}`;a["Proxy-Authorization"]=`Basic ${Buffer.from(f).toString("base64")}`}a.Hos...
L43: `;let c=(0,PM.parseProxyResponse)(i);i.write(`${s}\r
L44: `);let{connect:l,buffered:u}=await c;if(t.emit("proxyConnect",l),this.emit("proxyConnect",l,t),l.statusCode===200)return t.once("socket",OM),r.secureEndpoint?(Ps("Upgrading socket ...
...
L54: `)).replace(/\n/g,"%0A").replace(/\r/g,"%0D").replace(/"/g,"%22"),ea=(e,t,r)=>{if(t.length<r)throw new TypeError(`Failed to execute '${e}' on 'FormData': ${r} arguments required, b...
L55: --`+t;let r=new Uint8Array(t.length);for(let n=0;n<t.length;n++)r[n]=t.charCodeAt(n)
HighTrigger Reachable Command Output Exfiltration
A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/cli.jsView on unpkg · L42 1Trigger-reachable persistence chain: scripts.start -> dist/cli.js
L1: #!/usr/bin/env node
L2: "use strict";var TO=Object.create;var vd=Object.defineProperty;var RO=Object.getOwnPropertyDescriptor;var IO=Object.getOwnPropertyNames;var PO=Object.getPrototypeOf,OO=Object.proto...
L3: `)}};xa.DataSanitizer=wd});var wg=B(va=>{"use strict";Object.defineProperty(va,"__esModule",{value:!0});va.ConsoleLogger=void 0;va.createLogger=LO;va.formatActionableError=NO;var k...
L4: \\[?(?:
...
L21: `+w+"}":"{"+k.join(",")+"}",n=w,y}}typeof mb.stringify!="function"&&(mb.stringify=function(l,u,d){var f;if(n="",i="",typeof d=="number")for(f=0;f<d;f+=1)i+=" ";else typeof d=="stri...
L22: `,r:"\r",t:" "},a,o=function(w){throw{name:"SyntaxError",message:w,at:r,text:a}},s=function(w){return w&&w!==n&&o("Expected
HighTrigger Reachable Persistence
A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/cli.jsView on unpkg · L1 127</plist>
L128: `;ut.default.writeFileSync(o,s,"utf-8");try{(0,at.execSync)(`launchctl unload "${o}" 2>/dev/null || true`),(0,at.execSync)(`launchctl load -w "${o}"`)}catch(c){this.logger.debug("l...
L129: \u{1F4A1} Worker s\u1EBD t\u1EF1 kh\u1EDFi \u0111\u1ED9ng c\xF9ng macOS sau khi b\u1EADt m\xE1y ho\u1EB7c s\u1EADp ngu\u1ED3n.`}}if(t==="win32"){let a=`"${r}" "${n}" start`,o=!1;tr...
...
L137: C\xDA PH\xC1P:
L138: npx @softtynet/zplus-worker [l\u1EC7nh] [t\xF9y ch\u1ECDn]
L139:
HighRuntime Package Install
Package source invokes a package manager install command at runtime.
dist/cli.jsView on unpkg · L127 1#!/usr/bin/env node
L2: "use strict";var TO=Object.create;var vd=Object.defineProperty;var RO=Object.getOwnPropertyDescriptor;var IO=Object.getOwnPropertyNames;var PO=Object.getPrototypeOf,OO=Object.proto...
L3: `)}};xa.DataSanitizer=wd});var wg=B(va=>{"use strict";Object.defineProperty(va,"__esModule",{value:!0});va.ConsoleLogger=void 0;va.createLogger=LO;va.formatActionableError=NO;var k...
L4: \\[?(?:
...
L21: `+w+"}":"{"+k.join(",")+"}",n=w,y}}typeof mb.stringify!="function"&&(mb.stringify=function(l,u,d){var f;if(n="",i="",typeof d=="number")for(f=0;f<d;f+=1)i+=" ";else typeof d=="stri...
L22: `,r:"\r",t:" "},a,o=function(w){throw{name:"SyntaxError",message:w,at:r,text:a}},s=function(w){return w&&w!==n&&o("Expected '"+w+"' instead of '"+n+"'"),n=a.charAt(r),r+=1,n},c=fun...
L23: R
MediumInstall Persistence
Source writes installer persistence such as shell profile or service configuration.
dist/cli.jsView on unpkg · L1 1#!/usr/bin/env node
L2: "use strict";var TO=Object.create;var vd=Object.defineProperty;var RO=Object.getOwnPropertyDescriptor;var IO=Object.getOwnPropertyNames;var PO=Object.getPrototypeOf,OO=Object.proto...
L3: `)}};xa.DataSanitizer=wd});var wg=B(va=>{"use strict";Object.defineProperty(va,"__esModule",{value:!0});va.ConsoleLogger=void 0;va.createLogger=LO;va.formatActionableError=NO;var k...
L4: \\[?(?:
...
L21: `+w+"}":"{"+k.join(",")+"}",n=w,y}}typeof mb.stringify!="function"&&(mb.stringify=function(l,u,d){var f;if(n="",i="",typeof d=="number")for(f=0;f<d;f+=1)i+=" ";else typeof d=="stri...
L22: `,r:"\r",t:" "},a,o=function(w){throw{name:"SyntaxError",message:w,at:r,text:a}},s=function(w){return w&&w!==n&&o("Expected '"+w+"' instead of '"+n+"'"),n=a.charAt(r),r+=1,n},c=fun...
L23: R
LowWeak Crypto
Package source references weak cryptographic algorithms.
dist/cli.jsView on unpkg · L1