This document describes the management of vulnerabilities for the project and all modules within the organization.
Importing the package synchronously executes a hidden, 4 MB obfuscated configuration module. Its imported value is unused by the advertised middleware.
Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkglib/config.js is a 4.08 MB single-line obfuscated program with runtime string-decoding logic.
lib/config.jsView on unpkg · L1Source fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/tools.jsView on unpkgSource downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkglib/config.js is a 4.08 MB single-line obfuscated program with runtime string-decoding logic.
lib/config.jsView on unpkg · L1Source fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/tools.jsView on unpkg