This document describes the management of vulnerabilities for the project and all modules within the organization.
Importing the package executes an obfuscated payload. It creates hidden detached processes and sends host/user and supplied data to an obfuscated remote endpoint.
Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1