This document describes the management of vulnerabilities for the project and all modules within the organization.
A normal runtime import exfiltrates all environment variables and runs server-supplied code. No install hook is needed for activation.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/initializeCaller.jsView on unpkg · L2Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/initializeCaller.jsView on unpkg · L2The initializer posts the complete process environment to an obfuscated external endpoint.
lib/initializeCaller.jsView on unpkg · L7It compiles and executes JavaScript returned by that endpoint with access to require.
lib/initializeCaller.jsView on unpkg · L12Package source references a known benign dynamic code generation pattern.
lib/initializeCaller.jsView on unpkg · L12Importing the main entry point immediately loads the hidden initializer.
index.jsView on unpkg · L7This report applies to chai-as-agile@2.4.7.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
lib/initializeCaller.jsView on unpkg · L2Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/initializeCaller.jsView on unpkg · L2The initializer posts the complete process environment to an obfuscated external endpoint.
lib/initializeCaller.jsView on unpkg · L7It compiles and executes JavaScript returned by that endpoint with access to require.
lib/initializeCaller.jsView on unpkg · L12Package source references a known benign dynamic code generation pattern.
lib/initializeCaller.jsView on unpkg · L12Importing the main entry point immediately loads the hidden initializer.
index.jsView on unpkg · L7