1Source sends the broad process environment to a literal external destination.
L1: #!/usr/bin/env node
L2: var hI="http://localhost:8787",Ba="anyray-placeholder",Ie=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},Ye=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await pe(o,e),await AI(e,384),await EI(e)}finally{await jt(o,{force:!0}).catch(()=>{})}},Ky=1,My=3e4,xI=5e3,II=/^[a-f0-9]{64}$/,Gy=e=>`${e}.pending`,OI=e=>`${e}.lock`,iu=e=>{if(...
L4: `,{mode:384})}catch(a){throw await Tr(e,{recursive:!0,force:!0}).catch(()=>{}),a}return async()=>{try{JSON.parse(await Wa(t,"utf-8")).nonce===r&&await Tr(e,{recursive:!0,force:!0})...
L5: `,{mode:384}),await hu(r,384);try{await pe(r,n)}catch(o){throw await Tr(r,{force:!0}).catch(()=>{}),o}},te=async e=>{let t=await z
CriticalHardcoded Runtime Data Exfiltration
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L1 1#!/usr/bin/env node
L2: var hI="http://localhost:8787",Ba="anyray-placeholder",Ie=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},Ye=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await pe(o,e),await AI(e,384),await EI(e)}finally{await jt(o,{force:!0}).catch(()=>{})}},Ky=1,My=3e4,xI=5e3,II=/^[a-f0-9]{64}$/,Gy=e=>`${e}.pending`,OI=e=>`${e}.lock`,iu=e=>{if(...
HighChild Process
Package source references child process execution.
dist/index.jsView on unpkg · L1 114`).map(VT).join(" + [Environment]::NewLine + "),ZT=(e={})=>{let t={...jT,...e},n=()=>t.platform()==="win32",r=async()=>{let i=(await Lc(Ct(),hn))?.find(c=>c.startsWith("export COPI...
L115: `)):H&&ie&&await Ds(B,{force:!0}),await Tc(c,V,hn)}catch(L){try{X!==void 0&&ie?await fe(B,X):ie&&await Ds(B,{force:!0})}catch{throw new Error("Copilot CLI environment update failed...
L116: import { spawn } from "node:child_process"
1#!/usr/bin/env node
L2: var hI="http://localhost:8787",Ba="anyray-placeholder",Ie=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},Ye=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await pe(o,e),await AI(e,384),await EI(e)}finally{await jt(o,{force:!0}).catch(()=>{})}},Ky=1,My=3e4,xI=5e3,II=/^[a-f0-9]{64}$/,Gy=e=>`${e}.pending`,OI=e=>`${e}.lock`,iu=e=>{if(...
HighSame File Env Network Execution
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L1 96`),!0):!1};var Lt=e=>{if(e.length<=4)return"\u2026";let t=/^([a-z0-9]{2,6}_)/i.exec(e)?.[1]??"";return e.length>t.length+4?`${t}\u2026${e.slice(-4)}`:`\u2026${e.slice(-4)}`};var Ee...
L97: `)):w&&y&&await fp(d,{force:!0}),await Tc(n,f)}catch(b){try{g!==void 0&&y?await fe(d,g):y&&await fp(d,{force:!0})}catch{throw new Error("shell environment update failed and credent...
L98: `)?a.slice(0,-2):a.endsWith(`
...
L103: `);$c("sqlite3",[e],{input:o,encoding:"utf-8",maxBuffer:wp,stdio:["pipe","ignore","pipe"]})}finally{try{WR(n,{recursive:!0,force:!0})}catch{}}},JR={kind:"sqlite3-cli",readItem:(e,t...
L104: `,{mode:384}),await pe(n,t)},u_=(e,t)=>e.generation||t.generation?!!(e.generation&&e.generation===t.generation):e.op===t.op&&e.requestedAt===t.requestedAt&&e.watcherPid===t.watcher...
L10
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L96 96Trigger-reachable command-output exfiltration chain: scripts.start -> dist/index.js
L96: `),!0):!1};var Lt=e=>{if(e.length<=4)return"\u2026";let t=/^([a-z0-9]{2,6}_)/i.exec(e)?.[1]??"";return e.length>t.length+4?`${t}\u2026${e.slice(-4)}`:`\u2026${e.slice(-4)}`};var Ee...
L97: `)):w&&y&&await fp(d,{force:!0}),await Tc(n,f)}catch(b){try{g!==void 0&&y?await fe(d,g):y&&await fp(d,{force:!0})}catch{throw new Error("shell environment update failed and credent...
L98: `)?a.slice(0,-2):a.endsWith(`
...
L103: `);$c("sqlite3",[e],{input:o,encoding:"utf-8",maxBuffer:wp,stdio:["pipe","ignore","pipe"]})}finally{try{WR(n,{recursive:!0,force:!0})}catch{}}},JR={kind:"sqlite3-cli",readItem:(e,t...
L104: `,{mode:384}),await pe(n,t)},u_=(e,t)=>e.generation||t.generation?!!(e.generation&&e.generation===t.gen
HighTrigger Reachable Command Output Exfiltration
A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/index.jsView on unpkg · L96 1Trigger-reachable persistence chain: scripts.start -> dist/index.js
L1: #!/usr/bin/env node
L2: var hI="http://localhost:8787",Ba="anyray-placeholder",Ie=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},Ye=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await pe(o,e),await AI(e,384),await EI(e)}finally{await jt(o,{force:!0}).catch(()=>{})}},Ky=1,My=3e4,xI=5e3,II=/^[a-f0-9]{64}$/,Gy=e=>`${e}.pending`,OI=e=>`${e}.lock`,iu=e=>{if(...
L4: `,{mode:384})}catch(a){throw await Tr(e,{recursive:!0,force:!0}).catch(()=>{}),a}return async()=>{try{JSON.parse(await Wa(t,"utf-8")).nonce===r&&await Tr(e,{recursive:!0,force:!0})...
L5: `,{mode:384}),await hu(r,384);try{await pe(r,n)}catch(o){throw await Tr(r,{force:!0}).catch(()=>{}),o}},te=async e=>{let t=await zy();try{aw
HighTrigger Reachable Persistence
A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/index.jsView on unpkg · L1 1#!/usr/bin/env node
L2: var hI="http://localhost:8787",Ba="anyray-placeholder",Ie=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},Ye=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await pe(o,e),await AI(e,384),await EI(e)}finally{await jt(o,{force:!0}).catch(()=>{})}},Ky=1,My=3e4,xI=5e3,II=/^[a-f0-9]{64}$/,Gy=e=>`${e}.pending`,OI=e=>`${e}.lock`,iu=e=>{if(...
L4: `,{mode:384})}catch(a){throw await Tr(e,{recursive:!0,force:!0}).catch(()=>{}),a}return async()=>{try{JSON.parse(await Wa(t,"utf-8")).nonce===r&&await Tr(e,{recursive:!0,force:!0})...
L5: `,{mode:384}),await hu(r,384);try{await pe(r,n)}catch(o){throw await Tr(r,{force:!0}).catch(()=>{}),o}},te=async e=>{let t=await zy();try{await qy(e)}finally{await t()}},Qy=async e...
L6: `)},ln=(e,t={})=>{le
HighBase64 Obscured Url
Source decodes a Base64-obscured HTTP endpoint at runtime.
dist/index.jsView on unpkg · L1 1#!/usr/bin/env node
L2: var hI="http://localhost:8787",Ba="anyray-placeholder",Ie=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},Ye=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await pe(o,e),await AI(e,384),await EI(e)}finally{await jt(o,{force:!0}).catch(()=>{})}},Ky=1,My=3e4,xI=5e3,II=/^[a-f0-9]{64}$/,Gy=e=>`${e}.pending`,OI=e=>`${e}.lock`,iu=e=>{if(...
L4: `,{mode:384})}catch(a){throw await Tr(e,{recursive:!0,force:!0}).catch(()=>{}),a}return async()=>{try{JSON.parse(await Wa(t,"utf-8")).nonce===r&&await Tr(e,{recursive:!0,force:!0})...
L5: `,{mode:384}),await hu(r,384);try{await pe(r,n)}catch(o){throw await Tr(r,{force:!0}).catch(()=>{}),o}},te=async e=>{let t=await zy();try{await qy(e)}finally{await t()}},Qy=async e...
L6: `)},ln=(e,t={})=>{le
MediumInstall Persistence
Source writes installer persistence such as shell profile or service configuration.
dist/index.jsView on unpkg · L1