1Source sends the broad process environment to a literal external destination.
L1: #!/usr/bin/env node
L2: var bR="http://localhost:8787",Qa="anyray-placeholder",xe=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},Ze=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await he(o,e),await IR(e,384),await _R(e)}finally{await Xt(o,{force:!0}).catch(()=>{})}},gg=1,ug=3e4,TR=5e3,PR=/^[a-f0-9]{64}$/,wg=e=>`${e}.pending`,LR=e=>`${e}.lock`,vu=e=>{if(...
L4: `,{mode:384})}catch(a){throw await Ur(e,{recursive:!0,force:!0}).catch(()=>{}),a}return async()=>{try{JSON.parse(await ns(t,"utf-8")).nonce===r&&await Ur(e,{recursive:!0,force:!0})...
L5: `,{mode:384}),await _u(r,384);try{await he(r,n)}catch(o){throw await Ur(r,{force:!0}).catch(()=>{}),o}},re=async e=>{let t=await E
CriticalHardcoded Runtime Data Exfiltration
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/index.jsView on unpkg · L1 1#!/usr/bin/env node
L2: var bR="http://localhost:8787",Qa="anyray-placeholder",xe=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},Ze=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await he(o,e),await IR(e,384),await _R(e)}finally{await Xt(o,{force:!0}).catch(()=>{})}},gg=1,ug=3e4,TR=5e3,PR=/^[a-f0-9]{64}$/,wg=e=>`${e}.pending`,LR=e=>`${e}.lock`,vu=e=>{if(...
HighChild Process
Package source references child process execution.
dist/index.jsView on unpkg · L1 114`).map(rD).join(" + [Environment]::NewLine + "),aD=(e={})=>{let t={...nD,...e},n=()=>t.platform()==="win32",r=async()=>{let i=(await zc(At(),bn))?.find(c=>c.startsWith("export COPI...
L115: `)):Z&&z&&await Ys($,{force:!0}),await Xc(c,Y,bn)}catch(De){try{W!==void 0&&z?await pe($,W):z&&await Ys($,{force:!0})}catch{throw new Error("Copilot CLI environment update failed a...
L116: import { spawn } from "node:child_process"
1#!/usr/bin/env node
L2: var bR="http://localhost:8787",Qa="anyray-placeholder",xe=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},Ze=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await he(o,e),await IR(e,384),await _R(e)}finally{await Xt(o,{force:!0}).catch(()=>{})}},gg=1,ug=3e4,TR=5e3,PR=/^[a-f0-9]{64}$/,wg=e=>`${e}.pending`,LR=e=>`${e}.lock`,vu=e=>{if(...
HighSame File Env Network Execution
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L1 1#!/usr/bin/env node
L2: var bR="http://localhost:8787",Qa="anyray-placeholder",xe=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},Ze=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await he(o,e),await IR(e,384),await _R(e)}finally{await Xt(o,{force:!0}).catch(()=>{})}},gg=1,ug=3e4,TR=5e3,PR=/^[a-f0-9]{64}$/,wg=e=>`${e}.pending`,LR=e=>`${e}.lock`,vu=e=>{if(...
L4: `,{mode:384})}catch(a){throw await Ur(e,{recursive:!0,force:!0}).catch(()=>{}),a}return async()=>{try{JSON.parse(await ns(t,"utf-8")).nonce===r&&await Ur(e,{recursive:!0,force:!0})...
L5: `,{mode:384}),await _u(r,384);try{await he(r,n)}catch(o){throw await Ur(r,{force:!0}).catch(()=>{}),o}},re=async e=>{let t=await Eg();try{await Ig(e)}finally{await t()}},xg=async e...
L6: `)},pn=(e,t={})=>{le
HighCredential Exfiltration
Source combines credential-like environment material and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L1 •Manifest-reachable source captures an API credential, sends it to a fixed unofficial gateway, and persists that redirection in agent or shell configuration.
dist/index.js:
var bR="http://localhost:8787",Qa="anyray-placeholder",xe=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},Ze=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
`),await he(o,e),await IR(e,384),await _R(e)}finally{await Xt(o,{force:!0}).catch(()=>{})}},gg=1,ug=3e4,TR=5e3,PR=/^[a-f0-9]{64}$/,wg=e=>`${e}.pending`,LR=e=>`${e}.lock`,vu=e=>{if(...
`)},pn=(e,t={})=>{let n=e.byoUpstream,r=!n&&X(e,"anthropic"),o=de({...e.metadata,tool:e.metadata.tool??"claude-code"}),a=t.includeClientKey!==!1&&!((r||n)&&e.viaLocalProxy),s=t.inc...
`)){let u=d.indexOf(":");if(u>0&&d.slice(0,u).trim().toLowerCase()===l)retur
HighCredential Redirect Persistence
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index.jsView on unpkg 96`),!0):!1};var Mt=e=>{if(e.length<=4)return"\u2026";let t=/^([a-z0-9]{2,6}_)/i.exec(e)?.[1]??"";return e.length>t.length+4?`${t}\u2026${e.slice(-4)}`:`\u2026${e.slice(-4)}`};var ve...
L97: `)):w&&y&&await Op(d,{force:!0}),await Xc(n,f)}catch(b){try{g!==void 0&&y?await pe(d,g):y&&await Op(d,{force:!0})}catch{throw new Error("shell environment update failed and credent...
L98: `)?a.slice(0,-2):a.endsWith(`
...
L103: `);el("sqlite3",[e],{input:o,encoding:"utf-8",maxBuffer:Dp,stdio:["pipe","ignore","pipe"]})}finally{try{Y_(n,{recursive:!0,force:!0})}catch{}}},tT={kind:"sqlite3-cli",readItem:(e,t...
L104: `,{mode:384}),await he(n,t)},yT=(e,t)=>e.generation||t.generation?!!(e.generation&&e.generation===t.generation):e.op===t.op&&e.requestedAt===t.requestedAt&&e.watcherPid===t.watcher...
L10
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L96 1Trigger-reachable credential exfiltration chain: scripts.start -> dist/index.js
L1: #!/usr/bin/env node
L2: var bR="http://localhost:8787",Qa="anyray-placeholder",xe=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},Ze=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await he(o,e),await IR(e,384),await _R(e)}finally{await Xt(o,{force:!0}).catch(()=>{})}},gg=1,ug=3e4,TR=5e3,PR=/^[a-f0-9]{64}$/,wg=e=>`${e}.pending`,LR=e=>`${e}.lock`,vu=e=>{if(...
L4: `,{mode:384})}catch(a){throw await Ur(e,{recursive:!0,force:!0}).catch(()=>{}),a}return async()=>{try{JSON.parse(await ns(t,"utf-8")).nonce===r&&await Ur(e,{recursive:!0,force:!0})...
L5: `,{mode:384}),await _u(r,384);try{await he(r,n)}catch(o){throw await Ur(r,{force:!0}).catch(()=>{}),o}},re=async e=>{let t=await
HighTrigger Reachable Credential Exfiltration
A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/index.jsView on unpkg · L1 96Trigger-reachable command-output exfiltration chain: scripts.start -> dist/index.js
L96: `),!0):!1};var Mt=e=>{if(e.length<=4)return"\u2026";let t=/^([a-z0-9]{2,6}_)/i.exec(e)?.[1]??"";return e.length>t.length+4?`${t}\u2026${e.slice(-4)}`:`\u2026${e.slice(-4)}`};var ve...
L97: `)):w&&y&&await Op(d,{force:!0}),await Xc(n,f)}catch(b){try{g!==void 0&&y?await pe(d,g):y&&await Op(d,{force:!0})}catch{throw new Error("shell environment update failed and credent...
L98: `)?a.slice(0,-2):a.endsWith(`
...
L103: `);el("sqlite3",[e],{input:o,encoding:"utf-8",maxBuffer:Dp,stdio:["pipe","ignore","pipe"]})}finally{try{Y_(n,{recursive:!0,force:!0})}catch{}}},tT={kind:"sqlite3-cli",readItem:(e,t...
L104: `,{mode:384}),await he(n,t)},yT=(e,t)=>e.generation||t.generation?!!(e.generation&&e.generation===t.gen
HighTrigger Reachable Command Output Exfiltration
A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/index.jsView on unpkg · L96 1Trigger-reachable persistence chain: scripts.start -> dist/index.js
L1: #!/usr/bin/env node
L2: var bR="http://localhost:8787",Qa="anyray-placeholder",xe=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},Ze=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await he(o,e),await IR(e,384),await _R(e)}finally{await Xt(o,{force:!0}).catch(()=>{})}},gg=1,ug=3e4,TR=5e3,PR=/^[a-f0-9]{64}$/,wg=e=>`${e}.pending`,LR=e=>`${e}.lock`,vu=e=>{if(...
L4: `,{mode:384})}catch(a){throw await Ur(e,{recursive:!0,force:!0}).catch(()=>{}),a}return async()=>{try{JSON.parse(await ns(t,"utf-8")).nonce===r&&await Ur(e,{recursive:!0,force:!0})...
L5: `,{mode:384}),await _u(r,384);try{await he(r,n)}catch(o){throw await Ur(r,{force:!0}).catch(()=>{}),o}},re=async e=>{let t=await Eg();try{aw
HighTrigger Reachable Persistence
A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/index.jsView on unpkg · L1 1#!/usr/bin/env node
L2: var bR="http://localhost:8787",Qa="anyray-placeholder",xe=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},Ze=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await he(o,e),await IR(e,384),await _R(e)}finally{await Xt(o,{force:!0}).catch(()=>{})}},gg=1,ug=3e4,TR=5e3,PR=/^[a-f0-9]{64}$/,wg=e=>`${e}.pending`,LR=e=>`${e}.lock`,vu=e=>{if(...
L4: `,{mode:384})}catch(a){throw await Ur(e,{recursive:!0,force:!0}).catch(()=>{}),a}return async()=>{try{JSON.parse(await ns(t,"utf-8")).nonce===r&&await Ur(e,{recursive:!0,force:!0})...
L5: `,{mode:384}),await _u(r,384);try{await he(r,n)}catch(o){throw await Ur(r,{force:!0}).catch(()=>{}),o}},re=async e=>{let t=await Eg();try{await Ig(e)}finally{await t()}},xg=async e...
L6: `)},pn=(e,t={})=>{le
HighBase64 Obscured Url
Source decodes a Base64-obscured HTTP endpoint at runtime.
dist/index.jsView on unpkg · L1 1#!/usr/bin/env node
L2: var bR="http://localhost:8787",Qa="anyray-placeholder",xe=e=>{let t=e?.trim();return!!(t&&/^ark_[A-Za-z0-9_-]{20,512}$/.test(t))},Ze=e=>{let t=e.trim().replace(/\/+$/,"");return t=...
L3: `),await he(o,e),await IR(e,384),await _R(e)}finally{await Xt(o,{force:!0}).catch(()=>{})}},gg=1,ug=3e4,TR=5e3,PR=/^[a-f0-9]{64}$/,wg=e=>`${e}.pending`,LR=e=>`${e}.lock`,vu=e=>{if(...
L4: `,{mode:384})}catch(a){throw await Ur(e,{recursive:!0,force:!0}).catch(()=>{}),a}return async()=>{try{JSON.parse(await ns(t,"utf-8")).nonce===r&&await Ur(e,{recursive:!0,force:!0})...
L5: `,{mode:384}),await _u(r,384);try{await he(r,n)}catch(o){throw await Ur(r,{force:!0}).catch(()=>{}),o}},re=async e=>{let t=await Eg();try{await Ig(e)}finally{await t()}},xg=async e...
L6: `)},pn=(e,t={})=>{le
MediumInstall Persistence
Source writes installer persistence such as shell profile or service configuration.
dist/index.jsView on unpkg · L1