104\r
L105: `+n)}function gc(t,e,n,r,i,a){if(t.listenerCount("wsClientError")){let o=new Error(i);Error.captureStackTrace(o,gc),t.emit("wsClientError",o,n,e)}else xg(n,r,i,a)}});import f7 from...
L106: `)){if(/^\s*#/.test(e))continue;let n=/^\s*root\s*=\s*(?<mountPoint>"[^"]*"|'[^']*'|[^#]*)/.exec(e);if(n)return n.groups.mountPoint.trim().replaceAll(/^["']|["']$/g,"")}}var b7=Y((...
104\r
L105: `+n)}function gc(t,e,n,r,i,a){if(t.listenerCount("wsClientError")){let o=new Error(i);Error.captureStackTrace(o,gc),t.emit("wsClientError",o,n,e)}else xg(n,r,i,a)}});import f7 from...
L106: `)){if(/^\s*#/.test(e))continue;let n=/^\s*root\s*=\s*(?<mountPoint>"[^"]*"|'[^']*'|[^#]*)/.exec(e);if(n)return n.groups.mountPoint.trim().replaceAll(/^["']|["']$/g,"")}}var b7=Y((...
6|| (${o} === "string" && ${i} && ${i} == +${i} && !(${i} % 1))`).assign(s,(0,re._)`+${i}`);return;case"boolean":r.elseIf((0,re._)`${i} === "false" || ${i} === 0 || ${i} === null`)....
L7: || ${o} === "boolean" || ${i} === null`).assign(s,(0,re._)`[${i}]`)}}}function ate({gen:t,parentData:e,parentDataProperty:n},r){t.if((0,re._)`${e} !== undefined`,()=>t.assign((0,re...
L8: missingProperty: ${r},
...
L10: deps: ${n}}`};var Cie={keyword:"dependencies",type:"object",schemaType:"object",error:vi.error,code(t){let[e,n]=Pie(t);g4(t,e),h4(t,n)}};function Pie({schema:t}){let e={},n={};for(...
L11: at `+t[n].toString();return e}function ioe(t){if(!t)throw new TypeError("argument namespace is required");var e=Hb(),n=Ml(e[1]),r=n[0];function i(a){Wb.call(i,a)}return i._file=r,i...
L12: `,"utf8")}
HighSame File Env Network Execution
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L6 •Manifest-reachable source captures an API credential, sends it to a fixed unofficial gateway, and persists that redirection in agent or shell configuration.
dist/index.js:
`}Yq.exports=Gde;function Gde(t,e,n){var r=n||{},i=r.env||process.env.NODE_ENV||"development",a=r.onerror;return function(o){var s,c,l;if(!o&&Gq(e)){oT("cannot 404 after headers se...
`;t.dashboardSseClients?.forEach(i=>{i.write(r)})}var ca=Y(()=>{"use strict"});import _o from"path";import{randomUUID as Gge}from"crypto";import{promises as Ls,renameSync as Kge}fr...
${" ".repeat(e)}}`}throw new TypeError(`Unsupported canonical JSON value: ${typeof t}`)}var am=Y(()=>{"use strict"});import{randomUUID as vhe}from"crypto";import qs from"path";imp...
`:""}function I5(t){return Buffer.byteLength(t,"utf8")}function mA(t){return
HighCredential Redirect Persistence
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index.jsView on unpkg 3var gK=Object.create;var Zw=Object.defineProperty;var hK=Object.getOwnPropertyDescriptor;var yK=Object.getOwnPropertyNames;var vK=Object.getPrototypeOf,bK=Object.prototype.hasOwnPr...
L4: `:""},this._extScope=e,this._scope=new zr.Scope({parent:e}),this._nodes=[new TP]}toString(){return this._root.render(this.opts)}name(e){return this._scope.name(e)}scopeName(e){retu...
L5: || (${o} == "string" && ${i} && ${i} == +${i})`).assign(s,(0,re._)`+${i}`);return;case"integer":r.elseIf((0,re._)`${o} === "boolean" || ${i} === null
L6: || (${o} === "string" && ${i} && ${i} == +${i} && !(${i} % 1))`).assign(s,(0,re._)`+${i}`);return;case"boolean":r.elseIf((0,re._)`${i} === "false" || ${i} === 0 || ${i} === null`)....
L7: || ${o} === "boolean" || ${i} === null`).assign(s,(0,re._)`[${i}]`)}}}function
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L3 3Trigger-reachable command-output exfiltration chain: scripts.start -> dist/index.js
L3: var gK=Object.create;var Zw=Object.defineProperty;var hK=Object.getOwnPropertyDescriptor;var yK=Object.getOwnPropertyNames;var vK=Object.getPrototypeOf,bK=Object.prototype.hasOwnPr...
L4: `:""},this._extScope=e,this._scope=new zr.Scope({parent:e}),this._nodes=[new TP]}toString(){return this._root.render(this.opts)}name(e){return this._scope.name(e)}scopeName(e){retu...
L5: || (${o} == "string" && ${i} && ${i} == +${i})`).assign(s,(0,re._)`+${i}`);return;case"integer":r.elseIf((0,re._)`${o} === "boolean" || ${i} === null
L6: || (${o} === "string" && ${i} && ${i} == +${i} && !(${i} % 1))`).assign(s,(0,re._)`+${i}`);return;case"boolean":r.elseIf((0,re._)`${i} === "false" || ${i} === 0 || ${i} === null`)...
HighTrigger Reachable Command Output Exfiltration
A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/index.jsView on unpkg · L3 •matchType = normalized_sha256
matchedPackage = @weppy/roblox-mcp@2.14.4
matchedPath = dist/index.js
matchedIdentity = npm:QHdlcHB5L3JvYmxveC1tY3A:2.14.4
similarity = 1.000
summary = normalized source hash matched finalized malicious source
HighKnown Malware Source Similarity
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkg •matchType = malicious_source_fingerprint_signature
signature = b49cbce28fe822dc
signatureType = suspicious_hashes
sourceLabel = final_verdict:malicious
matchedPackage = @weppy/roblox-mcp@2.14.4
matchedPath = dist/index.js
matchedIdentity = npm:QHdlcHB5L3JvYmxveC1tY3A:2.14.4
similarity = 1.000
shingleOverlap = 6
summary = package final verdict is malicious
HighKnown Malware Source Fingerprint Signature
Source fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/index.jsView on unpkg 6|| (${o} === "string" && ${i} && ${i} == +${i} && !(${i} % 1))`).assign(s,(0,re._)`+${i}`);return;case"boolean":r.elseIf((0,re._)`${i} === "false" || ${i} === 0 || ${i} === null`)....
L7: || ${o} === "boolean" || ${i} === null`).assign(s,(0,re._)`[${i}]`)}}}function ate({gen:t,parentData:e,parentDataProperty:n},r){t.if((0,re._)`${e} !== undefined`,()=>t.assign((0,re...
L8: missingProperty: ${r},
LowEval
Package source references a known benign dynamic code generation pattern.
dist/index.jsView on unpkg · L6 3var gK=Object.create;var Zw=Object.defineProperty;var hK=Object.getOwnPropertyDescriptor;var yK=Object.getOwnPropertyNames;var vK=Object.getPrototypeOf,bK=Object.prototype.hasOwnPr...
L4: `:""},this._extScope=e,this._scope=new zr.Scope({parent:e}),this._nodes=[new TP]}toString(){return this._root.render(this.opts)}name(e){return this._scope.name(e)}scopeName(e){retu...
L5: || (${o} == "string" && ${i} && ${i} == +${i})`).assign(s,(0,re._)`+${i}`);return;case"integer":r.elseIf((0,re._)`${o} === "boolean" || ${i} === null
L6: || (${o} === "string" && ${i} && ${i} == +${i} && !(${i} % 1))`).assign(s,(0,re._)`+${i}`);return;case"boolean":r.elseIf((0,re._)`${i} === "false" || ${i} === 0 || ${i} === null`)....
L7: || ${o} === "boolean" || ${i} === null`).assign(s,(0,re._)`[${i}]`)}}}function
LowWeak Crypto
Package source references weak cryptographic algorithms.
dist/index.jsView on unpkg · L3