41SERVICE_URL_DEFAULTS = Object.freeze({
L42: haansiApiBaseUrl: "https://api.haansi.co",
L43: localApiBaseUrl: "http://localhost:3000",
...
L55: function apiUrl() {
L56: return process.env.HAANSI_API_URL ?? DEFAULT_API_URL;
L57: }
...
L61: try {
L62: const creds = JSON.parse((0, import_node_fs.readFileSync)(CREDENTIALS_FILE, "utf-8"));
L63: if (typeof creds.token === "string" && creds.token) return creds.token;
...
L70: try {
L71: const binPath = (0, import_node_child_process.execSync)("which haansi", { encoding: "utf-8" }).trim();
L72: if (binPath) return binPath;
CriticalRemote Asset Decode Execute
Source fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
dist/haansi.jsView on unpkg · L41 •Trigger-reachable chain: manifest.bin -> dist/haansi.js
Reachable file contains a blocking source-risk pattern.
CriticalTrigger Reachable Dangerous Capability
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/haansi.jsView on unpkg 70try {
L71: const binPath = (0, import_node_child_process.execSync)("which haansi", { encoding: "utf-8" }).trim();
L72: if (binPath) return binPath;
HighChild Process
Package source references child process execution.
dist/haansi.jsView on unpkg · L70 11779if (error2) {
L11780: if (command2.name === "exec" && error2.message === "EXECABORT Transaction discarded because of previous errors.") {
L11781: continue;
55714site.name = fn.name;
L55715: var deprecatedfn = new Function(
L55716: "fn",
41Detached bundled service listener: dist/haansi.js launches a Node helper and exposes a broad-bound HTTP listener.
L41: SERVICE_URL_DEFAULTS = Object.freeze({
L42: haansiApiBaseUrl: "https://api.haansi.co",
L43: localApiBaseUrl: "http://localhost:3000",
...
L55: function apiUrl() {
L56: return process.env.HAANSI_API_URL ?? DEFAULT_API_URL;
L57: }
...
L61: try {
L62: const creds = JSON.parse((0, import_node_fs.readFileSync)(CREDENTIALS_FILE, "utf-8"));
L63: if (typeof creds.token === "string" && creds.token) return creds.token;
...
L70: try {
L71: const binPath = (0, import_node_child_process.execSync)("which haansi", { encoding: "utf-8" }).trim();
L72: if (binPath) return binPath;
HighSpawned Bundled Service Listener
Source launches a detached bundled service that exposes a broad-bound HTTP listener.
dist/haansi.jsView on unpkg · L41 41Trigger-reachable persistence chain: manifest.bin -> dist/haansi.js
L41: SERVICE_URL_DEFAULTS = Object.freeze({
L42: haansiApiBaseUrl: "https://api.haansi.co",
L43: localApiBaseUrl: "http://localhost:3000",
...
L55: function apiUrl() {
L56: return process.env.HAANSI_API_URL ?? DEFAULT_API_URL;
L57: }
...
L61: try {
L62: const creds = JSON.parse((0, import_node_fs.readFileSync)(CREDENTIALS_FILE, "utf-8"));
L63: if (typeof creds.token === "string" && creds.token) return creds.token;
...
L70: try {
L71: const binPath = (0, import_node_child_process.execSync)("which haansi", { encoding: "utf-8" }).trim();
L72: if (binPath) return binPath;
HighTrigger Reachable Persistence
A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/haansi.jsView on unpkg · L41 11};
L12: var __commonJS = (cb, mod) => function __require() {
L13: return mod || (0, cb[__getOwnPropNames(cb)[0]])((mod = { exports: {} }).exports, mod), mod.exports;
MediumDynamic Require
Package source references dynamic require/import behavior.
dist/haansi.jsView on unpkg · L11 41SERVICE_URL_DEFAULTS = Object.freeze({
L42: haansiApiBaseUrl: "https://api.haansi.co",
L43: localApiBaseUrl: "http://localhost:3000",
...
L55: function apiUrl() {
L56: return process.env.HAANSI_API_URL ?? DEFAULT_API_URL;
L57: }
...
L61: try {
L62: const creds = JSON.parse((0, import_node_fs.readFileSync)(CREDENTIALS_FILE, "utf-8"));
L63: if (typeof creds.token === "string" && creds.token) return creds.token;
...
L70: try {
L71: const binPath = (0, import_node_child_process.execSync)("which haansi", { encoding: "utf-8" }).trim();
L72: if (binPath) return binPath;
MediumInstall Persistence
Source writes installer persistence such as shell profile or service configuration.
dist/haansi.jsView on unpkg · L41 41SERVICE_URL_DEFAULTS = Object.freeze({
L42: haansiApiBaseUrl: "https://api.haansi.co",
L43: localApiBaseUrl: "http://localhost:3000",
...
L55: function apiUrl() {
L56: return process.env.HAANSI_API_URL ?? DEFAULT_API_URL;
L57: }
...
L61: try {
L62: const creds = JSON.parse((0, import_node_fs.readFileSync)(CREDENTIALS_FILE, "utf-8"));
L63: if (typeof creds.token === "string" && creds.token) return creds.token;
...
L70: try {
L71: const binPath = (0, import_node_child_process.execSync)("which haansi", { encoding: "utf-8" }).trim();
L72: if (binPath) return binPath;
LowWeak Crypto
Package source references weak cryptographic algorithms.
dist/haansi.jsView on unpkg · L41