Copyright (c) React Training 2015-present
Installation launches a detached child process that retrieves and executes remote JavaScript. The remote payload can use Node require.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
lib/utils/index.jsView on unpkg · L2Source contains an obfuscated payload loader that reconstructs and executes hidden code.
lib/utils/smtp-connection/index.jsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/utils/smtp-connection/index.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
lib/utils/smtp-connection/index.jsView on unpkg · L9Package source references weak cryptographic algorithms.
lib/smtp-connection/index.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/shared/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/shared/index.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
lib/utils/index.jsView on unpkg · L2Source contains an obfuscated payload loader that reconstructs and executes hidden code.
lib/utils/smtp-connection/index.jsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/utils/smtp-connection/index.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
lib/utils/smtp-connection/index.jsView on unpkg · L9Package source references weak cryptographic algorithms.
lib/smtp-connection/index.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/shared/index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/shared/index.jsView on unpkg