This document describes the management of vulnerabilities for the project and all modules within the organization.
Importing the package main entry runs a large obfuscated script in lib/config.js. That script loads filesystem, process, child_process execSync and spawn, axios, and crypto while the rest of the strings stay encoded.
index.js loads child_process and requires ./lib/config as soon as the module is imported.
index.jsView on unpkg · L3Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
lib/config.jsView on unpkgpackage.json sets main to index.js for chai-as-relay 1.2.1 and defines only smoke scripts, with no install lifecycle hooks.
package.jsonView on unpkg · L1This report applies to chai-as-relay@1.2.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
index.js loads child_process and requires ./lib/config as soon as the module is imported.
index.jsView on unpkg · L3Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
lib/config.jsView on unpkgpackage.json sets main to index.js for chai-as-relay 1.2.1 and defines only smoke scripts, with no install lifecycle hooks.
package.jsonView on unpkg · L1