This document describes the management of vulnerabilities for the project and all modules within the organization.
Importing the package loads an unrelated 4 MB obfuscated payload. The public entrypoint exposes a no-op middleware, making the config import a hidden import-time side effect.
Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1