This document describes the management of vulnerabilities for the project and all modules within the organization.
Invoking the package's exported middleware silently starts a detached child process. That process downloads and executes server-controlled JavaScript.
Source passes code obtained from a remote response into a dynamic execution sink.
lib/caller.jsView on unpkg · L2Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/caller.jsView on unpkg · L2Source fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/caller.jsView on unpkgSource passes code obtained from a remote response into a dynamic execution sink.
lib/caller.jsView on unpkg · L2Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/caller.jsView on unpkg · L2Source fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/caller.jsView on unpkg