18import { accessSync, appendFileSync, chmodSync, closeSync, constants, createReadStream, createWriteStream, existsSync, fchmodSync, fstatSync, fsyncSync, linkSync, lstatSync, mkdirS...
L19: import * as http from "node:http";
L20: import * as https from "node:https";
...
L22: import { AsyncLocalStorage } from "node:async_hooks";
L23: import { execFile, execFileSync, spawn, spawnSync } from "node:child_process";
L24: import * as util$2 from "node:util";
...
L65: *
L66: * @private
L67: * @param {Error} err
...
L883: for (var i = 0; i < flen;) {
L884: if (f.charCodeAt(i) === 37 && i + 1 < flen) {
L885: lastPos = lastPos > -1 ? lastPos : 0;
CriticalCredential Exfiltration
Source appears to send environment or credential material to an external endpoint.
dist/connect-token-CneThoZJ.mjsView on unpkg · L18 18Trigger-reachable chain: manifest.exports -> dist/index.mjs -> dist/connect-token-CneThoZJ.mjs
L18: import { accessSync, appendFileSync, chmodSync, closeSync, constants, createReadStream, createWriteStream, existsSync, fchmodSync, fstatSync, fsyncSync, linkSync, lstatSync, mkdirS...
L19: import * as http from "node:http";
L20: import * as https from "node:https";
...
L22: import { AsyncLocalStorage } from "node:async_hooks";
L23: import { execFile, execFileSync, spawn, spawnSync } from "node:child_process";
L24: import * as util$2 from "node:util";
...
L65: *
L66: * @private
L67: * @param {Error} err
...
L883: for (var i = 0; i < flen;) {
L884: if (f.charCodeAt(i) === 37 && i + 1 < flen) {
L885: lastPos = lastPos > -1 ? lastPos : 0;
CriticalTrigger Reachable Dangerous Capability
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/connect-token-CneThoZJ.mjsView on unpkg · L18 •matchType = previous_version_dangerous_delta
matchedPackage = first-tree@0.5.19
matchedIdentity = npm:Zmlyc3QtdHJlZQ:0.5.19
similarity = 0.933
summary = stored previous version shares package body but lacks this dangerous source file
CriticalPrevious Version Dangerous Delta
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/connect-token-CneThoZJ.mjsView on unpkg 22import { AsyncLocalStorage } from "node:async_hooks";
L23: import { execFile, execFileSync, spawn, spawnSync } from "node:child_process";
L24: import * as util$2 from "node:util";
HighChild Process
Package source references child process execution.
dist/connect-token-CneThoZJ.mjsView on unpkg · L22 20867process.argv[0],
L20868: ...process.execArgv,
L20869: ...process.argv.slice(1)
•Manifest-reachable source captures an API credential, sends it to a fixed unofficial gateway, and persists that redirection in agent or shell configuration.
dist/connect-token-CneThoZJ.mjs:
import { accessSync, appendFileSync, chmodSync, closeSync, constants, createReadStream, createWriteStream, existsSync, fchmodSync, fstatSync, fsyncSync, linkSync, lstatSync, mkdirS...
import { createInterface } from "node:readline";
import { chmod, lstat, mkdir, mkdtemp, open, readFile as readFile$1, readdir as readdir$1, readlink, realpath, rename, rm, stat, symlink, writeFile } from "node:fs/promises";
const readlinePromises = [];
readlinePromises.push(getContextLinesFromFile(file, ranges, cache));
await Promise.all(readlinePromises).catch(() => {
headers["Proxy-Authorization"] = `Basic ${Buffer.from(
HighCredential Redirect Persistence
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/connect-token-CneThoZJ.mjsView on unpkg •Manifest-reachable source resolves another installed package, overwrites its runtime code, and injects package-defined remote behavior.
dist/connect-token-CneThoZJ.mjs:
import { accessSync, appendFileSync, chmodSync, closeSync, constants, createReadStream, createWriteStream, existsSync, fchmodSync, fstatSync, fsyncSync, linkSync, lstatSync, mkdirS...
import { chmod, lstat, mkdir, mkdtemp, open, readFile as readFile$1, readdir as readdir$1, readlink, realpath, rename, rm, stat, symlink, writeFile } from "node:fs/promises";
//#region ../../node_modules/.pnpm/pino-std-serializers@7.1.0/node_modules/pino-std-serializers/lib/err-helpers.js
//#region ../../node_modules/.pnpm/pino-std-serializers@7.1.0/node_modules/pino-std-serializers/lib/err-proto.js
//#region ../../node_modules/.pnpm/pino-std-
HighEntrypoint Foreign Package Code Overwrite
Manifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/connect-token-CneThoZJ.mjsView on unpkg 18import { accessSync, appendFileSync, chmodSync, closeSync, constants, createReadStream, createWriteStream, existsSync, fchmodSync, fstatSync, fsyncSync, linkSync, lstatSync, mkdirS...
L19: import * as http from "node:http";
L20: import * as https from "node:https";
...
L22: import { AsyncLocalStorage } from "node:async_hooks";
L23: import { execFile, execFileSync, spawn, spawnSync } from "node:child_process";
L24: import * as util$2 from "node:util";
...
L65: *
L66: * @private
L67: * @param {Error} err
...
L883: for (var i = 0; i < flen;) {
L884: if (f.charCodeAt(i) === 37 && i + 1 < flen) {
L885: lastPos = lastPos > -1 ? lastPos : 0;
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/connect-token-CneThoZJ.mjsView on unpkg · L18 •Manifest-trigger-reachable source links an external AI-agent control path to a behavior-bearing write operation.
catch (error) {
options.log?.(`managed skills lock cleanup failed: ${error instanceof error ? error.message.slice(0, 300) : string(error)}`);
}
}
});
}
function freezeresult(resourceconfigversion, result) {
return object.freeze({
ok: result.failures.length === 0,
resourceconfigversion,
installed: object.freeze([...result.installed]),
skipped: object.freeze([...result.skipped]),
removed: object.freeze([...result.removed]),
teamskills: object.freeze([...result.teamskills]),
failures: object.freeze([...result.failures]),
staleteamsnapshot: result.staleteamsnapshot
});
}
function processmutexkey(workspace) {
try {
return realpathsync(resolve(workspace)
HighTrigger Reachable External Ai Agent Control Surface Mutation
Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/connect-token-CneThoZJ.mjsView on unpkg 18Trigger-reachable credential exfiltration chain: manifest.exports -> dist/index.mjs -> dist/connect-token-CneThoZJ.mjs
L18: import { accessSync, appendFileSync, chmodSync, closeSync, constants, createReadStream, createWriteStream, existsSync, fchmodSync, fstatSync, fsyncSync, linkSync, lstatSync, mkdirS...
L19: import * as http from "node:http";
L20: import * as https from "node:https";
...
L22: import { AsyncLocalStorage } from "node:async_hooks";
L23: import { execFile, execFileSync, spawn, spawnSync } from "node:child_process";
L24: import * as util$2 from "node:util";
...
L65: *
L66: * @private
L67: * @param {Error} err
...
L883: for (var i = 0; i < flen;) {
L884: if (f.charCodeAt(i) === 37 && i + 1 < flen) {
L885: lastPos = lastPos > -1 ? lastPos : 0;
HighTrigger Reachable Credential Exfiltration
A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/connect-token-CneThoZJ.mjsView on unpkg · L18 18Trigger-reachable persistence chain: manifest.exports -> dist/index.mjs -> dist/connect-token-CneThoZJ.mjs
L18: import { accessSync, appendFileSync, chmodSync, closeSync, constants, createReadStream, createWriteStream, existsSync, fchmodSync, fstatSync, fsyncSync, linkSync, lstatSync, mkdirS...
L19: import * as http from "node:http";
L20: import * as https from "node:https";
...
L22: import { AsyncLocalStorage } from "node:async_hooks";
L23: import { execFile, execFileSync, spawn, spawnSync } from "node:child_process";
L24: import * as util$2 from "node:util";
...
L65: *
L66: * @private
L67: * @param {Error} err
...
L883: for (var i = 0; i < flen;) {
L884: if (f.charCodeAt(i) === 37 && i + 1 < flen) {
L885: lastPos = lastPos > -1 ? lastPos : 0;
HighTrigger Reachable Persistence
A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/connect-token-CneThoZJ.mjsView on unpkg · L18 95299/**
L95300: * Validate an npm install spec (the part after `@` in `<pkg>@<spec>`). We
L95301: * accept either a known dist-tag string (`latest`, `alpha`, …) or an exact
...
L95304: * want to forward an attacker-controlled shell metacharacter from a
L95305: * (compromised) server welcome frame straight into `spawn`. spawn() already
L95306: * argv-escapes, but a `--registry=...` style spec would still be
HighRuntime Package Install
Package source invokes a package manager install command at runtime.
dist/connect-token-CneThoZJ.mjsView on unpkg · L95299 •stage = ast_semantic_analysis; reason = ast_path_work_budget_exceeded; limitedFiles = 1
HighSemantic Analysis Limited
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/connect-token-CneThoZJ.mjsView on unpkg •matchType = token_shingles
matchedPackage = first-tree-staging@0.5.19-staging.1098.1
matchedPath = dist/connect-token-DteeikB-.mjs
matchedIdentity = npm:Zmlyc3QtdHJlZS1zdGFnaW5n:0.5.19-staging.1098.1
similarity = 1.000
shingleOverlap = 48
summary = source token shingles overlapped finalized malicious source
HighKnown Malware Source Similarity
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/connect-token-CneThoZJ.mjsView on unpkg 18import { accessSync, appendFileSync, chmodSync, closeSync, constants, createReadStream, createWriteStream, existsSync, fchmodSync, fstatSync, fsyncSync, linkSync, lstatSync, mkdirS...
L19: import * as http from "node:http";
L20: import * as https from "node:https";
...
L22: import { AsyncLocalStorage } from "node:async_hooks";
L23: import { execFile, execFileSync, spawn, spawnSync } from "node:child_process";
L24: import * as util$2 from "node:util";
...
L65: *
L66: * @private
L67: * @param {Error} err
...
L883: for (var i = 0; i < flen;) {
L884: if (f.charCodeAt(i) === 37 && i + 1 < flen) {
L885: lastPos = lastPos > -1 ? lastPos : 0;
MediumInstall Persistence
Source writes installer persistence such as shell profile or service configuration.
dist/connect-token-CneThoZJ.mjsView on unpkg · L18