1Source sends the broad process environment to a literal external destination.
L1: #!/usr/bin/env node
L2: var rx="http://localhost:8787",Da="anyray-placeholder",Ee=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},je=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await ue(o,e),await dx(e,384),await hx(e)}finally{await Kt(o,{force:!0}).catch(()=>{})}},py=1,sy=3e4,mx=5e3,yx=/^[a-f0-9]{64}$/,fy=e=>`${e}.pending`,gx=e=>`${e}.lock`,Wd=e=>{if(...
L4: `,{mode:384})}catch(a){throw await Ir(e,{recursive:!0,force:!0}).catch(()=>{}),a}return async()=>{try{JSON.parse(await $a(t,"utf-8")).nonce===r&&await Ir(e,{recursive:!0,force:!0})...
L5: `,{mode:384}),await Jd(r,384);try{await ue(r,n)}catch(o){throw await Ir(r,{force:!0}).catch(()=>{}),o}},te=async e=>{let t=await k
CriticalHardcoded Runtime Data Exfiltration
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L1 1#!/usr/bin/env node
L2: var rx="http://localhost:8787",Da="anyray-placeholder",Ee=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},je=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await ue(o,e),await dx(e,384),await hx(e)}finally{await Kt(o,{force:!0}).catch(()=>{})}},py=1,sy=3e4,mx=5e3,yx=/^[a-f0-9]{64}$/,fy=e=>`${e}.pending`,gx=e=>`${e}.lock`,Wd=e=>{if(...
HighChild Process
Package source references child process execution.
dist/index.jsView on unpkg · L1 114`).map(N_).join(" + [Environment]::NewLine + "),M_=(e={})=>{let t={...L_,...e},n=()=>t.platform()==="win32",r=async()=>{let i=(await Cc(bt(),un))?.find(c=>c.startsWith("export COPI...
L115: `)):U&&se&&await Rs(F,{force:!0}),await Ac(c,V,un)}catch(D){try{Z!==void 0&&se?await pe(F,Z):se&&await Rs(F,{force:!0})}catch{throw new Error("Copilot CLI environment update failed...
L116: import { spawn } from "node:child_process"
1#!/usr/bin/env node
L2: var rx="http://localhost:8787",Da="anyray-placeholder",Ee=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},je=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await ue(o,e),await dx(e,384),await hx(e)}finally{await Kt(o,{force:!0}).catch(()=>{})}},py=1,sy=3e4,mx=5e3,yx=/^[a-f0-9]{64}$/,fy=e=>`${e}.pending`,gx=e=>`${e}.lock`,Wd=e=>{if(...
HighSame File Env Network Execution
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L1 96`),!0):!1};var Pt=e=>{if(e.length<=4)return"\u2026";let t=/^([a-z0-9]{2,6}_)/i.exec(e)?.[1]??"";return e.length>t.length+4?`${t}\u2026${e.slice(-4)}`:`\u2026${e.slice(-4)}`};var ve...
L97: `)):w&&y&&await Xu(d,{force:!0}),await Ac(n,f)}catch(b){try{g!==void 0&&y?await pe(d,g):y&&await Xu(d,{force:!0})}catch{throw new Error("shell environment update failed and credent...
L98: `)?a.slice(0,-2):a.endsWith(`
...
L103: `);Ec("sqlite3",[e],{input:o,encoding:"utf-8",maxBuffer:ep,stdio:["pipe","ignore","pipe"]})}finally{try{_R(n,{recursive:!0,force:!0})}catch{}}},BR={kind:"sqlite3-cli",readItem:(e,t...
L104: `,{mode:384}),await ue(n,t)},eO=(e,t)=>e.generation||t.generation?!!(e.generation&&e.generation===t.generation):e.op===t.op&&e.requestedAt===t.requestedAt&&e.watcherPid===t.watcher...
L10
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L96 96Trigger-reachable command-output exfiltration chain: scripts.start -> dist/index.js
L96: `),!0):!1};var Pt=e=>{if(e.length<=4)return"\u2026";let t=/^([a-z0-9]{2,6}_)/i.exec(e)?.[1]??"";return e.length>t.length+4?`${t}\u2026${e.slice(-4)}`:`\u2026${e.slice(-4)}`};var ve...
L97: `)):w&&y&&await Xu(d,{force:!0}),await Ac(n,f)}catch(b){try{g!==void 0&&y?await pe(d,g):y&&await Xu(d,{force:!0})}catch{throw new Error("shell environment update failed and credent...
L98: `)?a.slice(0,-2):a.endsWith(`
...
L103: `);Ec("sqlite3",[e],{input:o,encoding:"utf-8",maxBuffer:ep,stdio:["pipe","ignore","pipe"]})}finally{try{_R(n,{recursive:!0,force:!0})}catch{}}},BR={kind:"sqlite3-cli",readItem:(e,t...
L104: `,{mode:384}),await ue(n,t)},eO=(e,t)=>e.generation||t.generation?!!(e.generation&&e.generation===t.gen
HighTrigger Reachable Command Output Exfiltration
A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/index.jsView on unpkg · L96 1Trigger-reachable persistence chain: scripts.start -> dist/index.js
L1: #!/usr/bin/env node
L2: var rx="http://localhost:8787",Da="anyray-placeholder",Ee=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},je=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await ue(o,e),await dx(e,384),await hx(e)}finally{await Kt(o,{force:!0}).catch(()=>{})}},py=1,sy=3e4,mx=5e3,yx=/^[a-f0-9]{64}$/,fy=e=>`${e}.pending`,gx=e=>`${e}.lock`,Wd=e=>{if(...
L4: `,{mode:384})}catch(a){throw await Ir(e,{recursive:!0,force:!0}).catch(()=>{}),a}return async()=>{try{JSON.parse(await $a(t,"utf-8")).nonce===r&&await Ir(e,{recursive:!0,force:!0})...
L5: `,{mode:384}),await Jd(r,384);try{await ue(r,n)}catch(o){throw await Ir(r,{force:!0}).catch(()=>{}),o}},te=async e=>{let t=await ky();try{aw
HighTrigger Reachable Persistence
A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/index.jsView on unpkg · L1 1#!/usr/bin/env node
L2: var rx="http://localhost:8787",Da="anyray-placeholder",Ee=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},je=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await ue(o,e),await dx(e,384),await hx(e)}finally{await Kt(o,{force:!0}).catch(()=>{})}},py=1,sy=3e4,mx=5e3,yx=/^[a-f0-9]{64}$/,fy=e=>`${e}.pending`,gx=e=>`${e}.lock`,Wd=e=>{if(...
L4: `,{mode:384})}catch(a){throw await Ir(e,{recursive:!0,force:!0}).catch(()=>{}),a}return async()=>{try{JSON.parse(await $a(t,"utf-8")).nonce===r&&await Ir(e,{recursive:!0,force:!0})...
L5: `,{mode:384}),await Jd(r,384);try{await ue(r,n)}catch(o){throw await Ir(r,{force:!0}).catch(()=>{}),o}},te=async e=>{let t=await ky();try{await Ay(e)}finally{await t()}},Cy=async e...
L6: `)},on=(e,t={})=>{le
HighBase64 Obscured Url
Source decodes a Base64-obscured HTTP endpoint at runtime.
dist/index.jsView on unpkg · L1 1#!/usr/bin/env node
L2: var rx="http://localhost:8787",Da="anyray-placeholder",Ee=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},je=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await ue(o,e),await dx(e,384),await hx(e)}finally{await Kt(o,{force:!0}).catch(()=>{})}},py=1,sy=3e4,mx=5e3,yx=/^[a-f0-9]{64}$/,fy=e=>`${e}.pending`,gx=e=>`${e}.lock`,Wd=e=>{if(...
L4: `,{mode:384})}catch(a){throw await Ir(e,{recursive:!0,force:!0}).catch(()=>{}),a}return async()=>{try{JSON.parse(await $a(t,"utf-8")).nonce===r&&await Ir(e,{recursive:!0,force:!0})...
L5: `,{mode:384}),await Jd(r,384);try{await ue(r,n)}catch(o){throw await Ir(r,{force:!0}).catch(()=>{}),o}},te=async e=>{let t=await ky();try{await Ay(e)}finally{await t()}},Cy=async e...
L6: `)},on=(e,t={})=>{le
MediumInstall Persistence
Source writes installer persistence such as shell profile or service configuration.
dist/index.jsView on unpkg · L1