This document describes the management of vulnerabilities for the project and all modules within the organization.
Importing the advertised main entrypoint immediately loads an opaque, heavily obfuscated payload. That payload accesses filesystem/platform APIs, runs child processes, and makes HTTP client requests.
Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1