A fast, validated, zero-dependency environment configuration toolkit for Node.js
A hidden payload is extracted from a bundled JPEG and executed as an encoded PowerShell command. No user action beyond importing the package or starting its CLI is required.
Code reads a payload from a JPEG file located beside the module.
dist/decode.jsView on unpkg · L6The payload is assembled into a PowerShell command with the EncodedCommand switch.
dist/decode.jsView on unpkg · L54The code writes a self-deleting VBScript that launches the command hidden and detached.
dist/decode.jsView on unpkg · L67Package source references dynamic require/import behavior.
dist/decode.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/cli.cjs#virtual:normalized:round1View on unpkgThe manifest exposes the bundled CJS module as the package entrypoint and the bundled CLI as an executable.
package.jsonView on unpkg · L5This report applies to better-envforge@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Code reads a payload from a JPEG file located beside the module.
dist/decode.jsView on unpkg · L6The payload is assembled into a PowerShell command with the EncodedCommand switch.
dist/decode.jsView on unpkg · L54The code writes a self-deleting VBScript that launches the command hidden and detached.
dist/decode.jsView on unpkg · L67Package source references dynamic require/import behavior.
dist/decode.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/cli.cjs#virtual:normalized:round1View on unpkgThe manifest exposes the bundled CJS module as the package entrypoint and the bundled CLI as an executable.
package.jsonView on unpkg · L5