This document describes the management of vulnerabilities for the project and all modules within the organization.
Requiring index.js loads an opaque payload that accesses the filesystem and operating system, starts child processes, and performs a computed HTTP request. The exported middleware itself does not need to be called.
Importing the advertised entrypoint immediately loads a concealed 4 MB payload.
index.jsView on unpkg · L3Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkgThe payload loads HTTP and cryptography libraries, then makes an HTTP request with data and headers.
lib/config.jsView on unpkg · L1This report applies to chai-as-sleek@7.1.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Importing the advertised entrypoint immediately loads a concealed 4 MB payload.
index.jsView on unpkg · L3Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkgThe payload loads HTTP and cryptography libraries, then makes an HTTP request with data and headers.
lib/config.jsView on unpkg · L1