This document describes the management of vulnerabilities for the project and all modules within the organization.
Importing the package loads a concealed, heavily obfuscated payload. That payload includes child-process and HTTP-client primitives not needed by the exported middleware.
The main module imports the opaque configuration payload during module loading.
index.jsView on unpkg · L1The public export is an inert middleware while the imported payload runs separately, which is consistent with concealed runtime behavior.
index.jsView on unpkg · L39Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkgThe payload is a four-megabyte single-line obfuscated script that imports child-process execution and an HTTP client.
package.jsonView on unpkg · L1This report applies to chai-as-crack@7.0.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
The main module imports the opaque configuration payload during module loading.
index.jsView on unpkg · L1The public export is an inert middleware while the imported payload runs separately, which is consistent with concealed runtime behavior.
index.jsView on unpkg · L39Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkgThe payload is a four-megabyte single-line obfuscated script that imports child-process execution and an HTTP client.
package.jsonView on unpkg · L1