8`:case"\u2028":case"\u2029":return ae(),"";case"\r":return ae(),Lu()===`
L9: `&&ae(),"";case"1":case"2":case"3":case"4":case"5":case"6":case"7":case"8":case"9":throw or(ae());case void 0:throw or(ae())}return ae()}function aQe(){let e="",t=Lu();if(!cn.isHex...
L10: `+s;C=D.join(b),g=`{
...
L27: `+a+x+`,
L28: `+D+"]"}return o.pop(),a=D,C}}}),jj=Fr((e,t)=>{var r=DQe(),n=IQe(),i={parse:r,stringify:n};t.exports=i}),Hj=Fr((e,t)=>{t.exports={LOCHDR:30,LOCSIG:67324752,LOCVER:4,LOCFLG:6,LOCHOW...
L29: `;if(ct.default.existsSync(e))try{if(ct.default.readFileSync(e,"utf-8")===r)return}catch{}YR(e),ct.default.writeFileSync(e,r,"utf-8")}function XA(e,t=""){return`http://127.0.0.1:${...
L30: `).replace(/\n{3,}/g,`
...
L49: base_url = "${XA(e,"/v1")}"
L50: wire_api = "responses"${o}`,OR(t,n),fI(e,n)
CriticalCredential Exfiltration
Source appears to send environment or credential material to an external endpoint.
dist/cli.jsView on unpkg · L8 215`+p+"}":"{"+m.join(",")+"}",n=p,d}}typeof Xee.stringify!="function"&&(Xee.stringify=function(c,l,f){var h;if(n="",i="",typeof f=="number")for(h=0;h<f;h+=1)i+=" ";else typeof f=="st...
L216: `,r:"\r",t:" "},s,o=function(p){throw{name:"SyntaxError",message:p,at:r,text:s}},a=function(p){return p&&p!==n&&o("Expected '"+p+"' instead of '"+n+"'"),n=s.charAt(r),r+=1,n},u=fun...
L217: Supported algorithms are:
L218: "HS256", "HS384", "HS512", "RS256", "RS384", "RS512", "PS256", "PS384", "PS512", "ES256", "ES384", "ES512" and "none".`,tE="secret must be a string or buffer",op="key must be a str...
L219: `});let l=c.join(";"),f=await e.crypto.sha256DigestHex(r),h=`${e.method.toUpperCase()}
...
L226: ${d}
L227: `+await e.crypto.sha256DigestHex(h),p=await rGe(e.crypto,e.securityCredentials.secre
CriticalRemote Asset Decode Execute
Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/cli.jsView on unpkg · L215 8Trigger-reachable chain: manifest.bin -> dist/cli.js
L8: `:case"\u2028":case"\u2029":return ae(),"";case"\r":return ae(),Lu()===`
L9: `&&ae(),"";case"1":case"2":case"3":case"4":case"5":case"6":case"7":case"8":case"9":throw or(ae());case void 0:throw or(ae())}return ae()}function aQe(){let e="",t=Lu();if(!cn.isHex...
L10: `+s;C=D.join(b),g=`{
...
L27: `+a+x+`,
L28: `+D+"]"}return o.pop(),a=D,C}}}),jj=Fr((e,t)=>{var r=DQe(),n=IQe(),i={parse:r,stringify:n};t.exports=i}),Hj=Fr((e,t)=>{t.exports={LOCHDR:30,LOCSIG:67324752,LOCVER:4,LOCFLG:6,LOCHOW...
L29: `;if(ct.default.existsSync(e))try{if(ct.default.readFileSync(e,"utf-8")===r)return}catch{}YR(e),ct.default.writeFileSync(e,r,"utf-8")}function XA(e,t=""){return`http://127.0.0.1:${...
L30: `).replace(/\n{3,}/g,`
...
L49: base_url = "${XA(e,"/v1
CriticalTrigger Reachable Dangerous Capability
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/cli.jsView on unpkg · L8 226${d}
L227: `+await e.crypto.sha256DigestHex(h),p=await rGe(e.crypto,e.securityCredentials.secretAccessKey,o,e.region,n),m=await uE(e.crypto,p,A),E=`${Wre} Credential=${e.securityCredentials.a...
L228: To learn more about authentication and Google APIs, visit:
215`+p+"}":"{"+m.join(",")+"}",n=p,d}}typeof Xee.stringify!="function"&&(Xee.stringify=function(c,l,f){var h;if(n="",i="",typeof f=="number")for(h=0;h<f;h+=1)i+=" ";else typeof f=="st...
L216: `,r:"\r",t:" "},s,o=function(p){throw{name:"SyntaxError",message:p,at:r,text:s}},a=function(p){return p&&p!==n&&o("Expected '"+p+"' instead of '"+n+"'"),n=s.charAt(r),r+=1,n},u=fun...
L217: Supported algorithms are:
...
L226: ${d}
L227: `+await e.crypto.sha256DigestHex(h),p=await rGe(e.crypto,e.securityCredentials.secretAccessKey,o,e.region,n),m=await uE(e.crypto,p,A),E=`${Wre} Credential=${e.securityCredentials.a...
L228: To learn more about authentication and Google APIs, visit:
HighSame File Env Network Execution
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli.jsView on unpkg · L215 215`+p+"}":"{"+m.join(",")+"}",n=p,d}}typeof Xee.stringify!="function"&&(Xee.stringify=function(c,l,f){var h;if(n="",i="",typeof f=="number")for(h=0;h<f;h+=1)i+=" ";else typeof f=="st...
L216: `,r:"\r",t:" "},s,o=function(p){throw{name:"SyntaxError",message:p,at:r,text:s}},a=function(p){return p&&p!==n&&o("Expected '"+p+"' instead of '"+n+"'"),n=s.charAt(r),r+=1,n},u=fun...
L217: Supported algorithms are:
...
L226: ${d}
L227: `+await e.crypto.sha256DigestHex(h),p=await rGe(e.crypto,e.securityCredentials.secretAccessKey,o,e.region,n),m=await uE(e.crypto,p,A),E=`${Wre} Credential=${e.securityCredentials.a...
L228: To learn more about authentication and Google APIs, visit:
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/cli.jsView on unpkg · L215 8`:case"\u2028":case"\u2029":return ae(),"";case"\r":return ae(),Lu()===`
L9: `&&ae(),"";case"1":case"2":case"3":case"4":case"5":case"6":case"7":case"8":case"9":throw or(ae());case void 0:throw or(ae())}return ae()}function aQe(){let e="",t=Lu();if(!cn.isHex...
L10: `+s;C=D.join(b),g=`{
...
L27: `+a+x+`,
L28: `+D+"]"}return o.pop(),a=D,C}}}),jj=Fr((e,t)=>{var r=DQe(),n=IQe(),i={parse:r,stringify:n};t.exports=i}),Hj=Fr((e,t)=>{t.exports={LOCHDR:30,LOCSIG:67324752,LOCVER:4,LOCFLG:6,LOCHOW...
L29: `;if(ct.default.existsSync(e))try{if(ct.default.readFileSync(e,"utf-8")===r)return}catch{}YR(e),ct.default.writeFileSync(e,r,"utf-8")}function XA(e,t=""){return`http://127.0.0.1:${...
L30: `).replace(/\n{3,}/g,`
...
L49: base_url = "${XA(e,"/v1")}"
L50: wire_api = "responses"${o}`,OR(t,n),fI(e,n)
HighCloud Metadata Access
Source reaches cloud instance metadata or link-local credential endpoints.
dist/cli.jsView on unpkg · L8 8Trigger-reachable credential exfiltration chain: manifest.bin -> dist/cli.js
L8: `:case"\u2028":case"\u2029":return ae(),"";case"\r":return ae(),Lu()===`
L9: `&&ae(),"";case"1":case"2":case"3":case"4":case"5":case"6":case"7":case"8":case"9":throw or(ae());case void 0:throw or(ae())}return ae()}function aQe(){let e="",t=Lu();if(!cn.isHex...
L10: `+s;C=D.join(b),g=`{
...
L27: `+a+x+`,
L28: `+D+"]"}return o.pop(),a=D,C}}}),jj=Fr((e,t)=>{var r=DQe(),n=IQe(),i={parse:r,stringify:n};t.exports=i}),Hj=Fr((e,t)=>{t.exports={LOCHDR:30,LOCSIG:67324752,LOCVER:4,LOCFLG:6,LOCHOW...
L29: `;if(ct.default.existsSync(e))try{if(ct.default.readFileSync(e,"utf-8")===r)return}catch{}YR(e),ct.default.writeFileSync(e,r,"utf-8")}function XA(e,t=""){return`http://127.0.0.1:${...
L30: `).replace(/\n{3,}/g,`
...
L49:
HighTrigger Reachable Credential Exfiltration
A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/cli.jsView on unpkg · L8 215Trigger-reachable command-output exfiltration chain: manifest.bin -> dist/cli.js
L215: `+p+"}":"{"+m.join(",")+"}",n=p,d}}typeof Xee.stringify!="function"&&(Xee.stringify=function(c,l,f){var h;if(n="",i="",typeof f=="number")for(h=0;h<f;h+=1)i+=" ";else typeof f=="st...
L216: `,r:"\r",t:" "},s,o=function(p){throw{name:"SyntaxError",message:p,at:r,text:s}},a=function(p){return p&&p!==n&&o("Expected '"+p+"' instead of '"+n+"'"),n=s.charAt(r),r+=1,n},u=fun...
L217: Supported algorithms are:
...
L226: ${d}
L227: `+await e.crypto.sha256DigestHex(h),p=await rGe(e.crypto,e.securityCredentials.secretAccessKey,o,e.region,n),m=await uE(e.crypto,p,A),E=`${Wre} Credential=${e.securityCredentials.a...
L228: To learn more about authentication and Google APIs, visit:
HighTrigger Reachable Command Output Exfiltration
A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/cli.jsView on unpkg · L215 993`).map(r=>r.trim()).filter(Boolean).join(`
L994: `)}async function Txe(){if(Wq)return{success:!1,message:"Update already in progress"};Wq=!0;try{try{let r=(0,Jq.join)(eQ.HOME_DIR,"pre-upgrade-backups");(0,Xv.mkdirSync)(r,{recursi...
L995: `,r);n>=0&&(r=n+1)}return r>0?e.substring(r):e},split(e,t){let r=e.trim().split(/\s+/);return r.length>t&&(r[t-1]=r.slice(t-1).join(" ")),r},extractColumns(e,t,r){let n=e.split(/(\...
HighRuntime Package Install
Package source invokes a package manager install command at runtime.
dist/cli.jsView on unpkg · L993 •stage = ast_semantic_analysis; reason = ast_path_work_budget_exceeded; limitedFiles = 1
HighSemantic Analysis Limited
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/cli.jsView on unpkg 27`+a+x+`,
L28: `+D+"]"}return o.pop(),a=D,C}}}),jj=Fr((e,t)=>{var r=DQe(),n=IQe(),i={parse:r,stringify:n};t.exports=i}),Hj=Fr((e,t)=>{t.exports={LOCHDR:30,LOCSIG:67324752,LOCVER:4,LOCFLG:6,LOCHOW...
L29: `;if(ct.default.existsSync(e))try{if(ct.default.readFileSync(e,"utf-8")===r)return}catch{}YR(e),ct.default.writeFileSync(e,r,"utf-8")}function XA(e,t=""){return`http://127.0.0.1:${...
MediumDynamic Require
Package source references dynamic require/import behavior.
dist/cli.jsView on unpkg · L27