This document describes the management of vulnerabilities for the project and all modules within the organization.
Importing the package loads an obfuscated payload. The payload combines process execution, dynamic code construction, filesystem access, and outbound HTTP through axios.
Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1