4Source sends the broad process environment to a literal external destination.
L4: const __filename = (await import("node:url")).fileURLToPath(import.meta.url);
L5: const __dirname = (await import("node:path")).dirname(__filename);
L6:
L7: var XG=Object.create;var pl=Object.defineProperty;var JG=Object.getOwnPropertyDescriptor;var QG=Object.getOwnPropertyNames;var ZG=Object.getPrototypeOf,e6=Object.prototype.hasOwnPr...
L8: `:10,t=typeof r=="string"?"\r":13;return r[r.length-1]===e&&(r=r.slice(0,r.length-1)),r[r.length-1]===t&&(r=r.slice(0,r.length-1)),r}});var nO=P((Dye,Ac)=>{"use strict";var yc=W("p...
L9: ${n.message}`:g,S=[_,e,r].filter(Boolean).join(`
L10: `);return h?(n.originalMessage=n.message,n.message=S):n=new Error(S),n.shortMessage=_,n.command=o,n.escapedCommand=a,n.exitCode=s,
CriticalHardcoded Runtime Data Exfiltration
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/create-cedar-app.jsView on unpkg · L4 •matchType = previous_version_dangerous_delta
matchedPackage = create-cedar-app@6.0.0
matchedIdentity = npm:Y3JlYXRlLWNlZGFyLWFwcA:6.0.0
similarity = 0.933
summary = stored previous version shares package body but lacks this dangerous source file
CriticalPrevious Version Dangerous Delta
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/create-cedar-app.jsView on unpkg 6L7: var XG=Object.create;var pl=Object.defineProperty;var JG=Object.getOwnPropertyDescriptor;var QG=Object.getOwnPropertyNames;var ZG=Object.getPrototypeOf,e6=Object.prototype.hasOwnPr...
L8: `:10,t=typeof r=="string"?"\r":13;return r[r.length-1]===e&&(r=r.slice(0,r.length-1)),r[r.length-1]===t&&(r=r.slice(0,r.length-1)),r}});var nO=P((Dye,Ac)=>{"use strict";var yc=W("p...
L9: ${n.message}`:g,S=[_,e,r].filter(Boolean).join(`
L10: `);return h?(n.originalMessage=n.message,n.message=S):n=new Error(S),n.shortMessage=_,n.command=o,n.escapedCommand=a,n.exitCode=s,n.signal=i,n.signalDescription=f,n.stdout=r,n.stde...
L11: `)];for(let[u,l]of c.entries()){if(n+=l,op.has(l)){let{groups:f}=new RegExp(`(?:\\${mC}(?<code>\\d+)m|\\${s_}(?<uri>.*)${n_})`).exec(c.slice(u).join(""))||{groups:{}};if(f.
HighSame File Env Network Execution
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/create-cedar-app.jsView on unpkg · L6 •Manifest-reachable source captures an API credential, sends it to a fixed unofficial gateway, and persists that redirection in agent or shell configuration.
dist/create-cedar-app.js:
`);return h?(n.originalMessage=n.message,n.message=S):n=new Error(S),n.shortMessage=_,n.command=o,n.escapedCommand=a,n.exitCode=s,n.signal=i,n.signalDescription=f,n.stdout=r,n.stde...
`+t,width:i=80}=e,s=(n+t).match(/[^\S\n]/g)||[];i-=s.length;let o=`.{1,${i}}([\\s\\u200B]+|$)|[^\\s\\u200B]+?([\\s\\u200B]+|$)`,a=r.trim(),c=new RegExp(o,"g"),u=a.match(c)||[];retu...
`),i+=r.charAt(s);return t&&n&&(i=`${t}${i}${n}`),i}function Gg(r){return Ob(r,{stringWidth:e=>[...e].length,stripAnsi:kg,wrap:Cb})}import{dirname as Db,resolve as Pb}from"path";im...
`));try{(await Pe.prompt({type:"select",name:"override-engine-err
HighCredential Redirect Persistence
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/create-cedar-app.jsView on unpkg 6L7: var XG=Object.create;var pl=Object.defineProperty;var JG=Object.getOwnPropertyDescriptor;var QG=Object.getOwnPropertyNames;var ZG=Object.getPrototypeOf,e6=Object.prototype.hasOwnPr...
L8: `:10,t=typeof r=="string"?"\r":13;return r[r.length-1]===e&&(r=r.slice(0,r.length-1)),r[r.length-1]===t&&(r=r.slice(0,r.length-1)),r}});var nO=P((Dye,Ac)=>{"use strict";var yc=W("p...
L9: ${n.message}`:g,S=[_,e,r].filter(Boolean).join(`
L10: `);return h?(n.originalMessage=n.message,n.message=S):n=new Error(S),n.shortMessage=_,n.command=o,n.escapedCommand=a,n.exitCode=s,n.signal=i,n.signalDescription=f,n.stdout=r,n.stde...
L11: `)];for(let[u,l]of c.entries()){if(n+=l,op.has(l)){let{groups:f}=new RegExp(`(?:\\${mC}(?<code>\\d+)m|\\${s_}(?<uri>.*)${n_})`).exec(c.slice(u).join(""))||{groups:{}};if(f.
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/create-cedar-app.jsView on unpkg · L6 4const __filename = (await import("node:url")).fileURLToPath(import.meta.url);
L5: const __dirname = (await import("node:path")).dirname(__filename);
L6:
L7: var XG=Object.create;var pl=Object.defineProperty;var JG=Object.getOwnPropertyDescriptor;var QG=Object.getOwnPropertyNames;var ZG=Object.getPrototypeOf,e6=Object.prototype.hasOwnPr...
L8: `:10,t=typeof r=="string"?"\r":13;return r[r.length-1]===e&&(r=r.slice(0,r.length-1)),r[r.length-1]===t&&(r=r.slice(0,r.length-1)),r}});var nO=P((Dye,Ac)=>{"use strict";var yc=W("p...
L9: ${n.message}`:g,S=[_,e,r].filter(Boolean).join(`
L10: `);return h?(n.originalMessage=n.message,n.message=S):n=new Error(S),n.shortMessage=_,n.command=o,n.escapedCommand=a,n.exitCode=s,n.signal=i,n.signalDescription=f,n.stdout=r,n.stde...
L11: `)];for(let[u,l]of
HighSandbox Evasion Gated Capability
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/create-cedar-app.jsView on unpkg · L4 6Trigger-reachable command-output exfiltration chain: manifest.bin -> dist/create-cedar-app.js
L6:
L7: var XG=Object.create;var pl=Object.defineProperty;var JG=Object.getOwnPropertyDescriptor;var QG=Object.getOwnPropertyNames;var ZG=Object.getPrototypeOf,e6=Object.prototype.hasOwnPr...
L8: `:10,t=typeof r=="string"?"\r":13;return r[r.length-1]===e&&(r=r.slice(0,r.length-1)),r[r.length-1]===t&&(r=r.slice(0,r.length-1)),r}});var nO=P((Dye,Ac)=>{"use strict";var yc=W("p...
L9: ${n.message}`:g,S=[_,e,r].filter(Boolean).join(`
L10: `);return h?(n.originalMessage=n.message,n.message=S):n=new Error(S),n.shortMessage=_,n.command=o,n.escapedCommand=a,n.exitCode=s,n.signal=i,n.signalDescription=f,n.stdout=r,n.stde...
L11: `)];for(let[u,l]of c.entries()){if(n+=l,op.has(l)){let{groups:f}=new RegExp(`(
HighTrigger Reachable Command Output Exfiltration
A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/create-cedar-app.jsView on unpkg · L6 •matchType = normalized_sha256
matchedPackage = create-cedar-app@6.0.2
matchedPath = dist/create-cedar-app.js
matchedIdentity = npm:Y3JlYXRlLWNlZGFyLWFwcA:6.0.2
similarity = 1.000
summary = normalized source hash matched finalized malicious source
HighKnown Malware Source Similarity
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/create-cedar-app.jsView on unpkg 2L3: const require = (await import("node:module")).createRequire(import.meta.url);
L4: const __filename = (await import("node:url")).fileURLToPath(import.meta.url);
MediumDynamic Require
Package source references dynamic require/import behavior.
dist/create-cedar-app.jsView on unpkg · L2