This document describes the management of vulnerabilities for the project and all modules within the organization.
The main export silently launches a detached worker on import or invocation. That worker retrieves code from a concealed endpoint and executes it locally.
Source passes code obtained from a remote response into a dynamic execution sink.
lib/caller.jsView on unpkg · L2Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/caller.jsView on unpkg · L2The spawned module decodes a concealed remote URL and fetches it with Axios.
lib/caller.jsView on unpkg · L12Importing the main export starts a detached Node process without user interaction.
index.jsView on unpkg · L32Importing the main export starts a detached Node process without user interaction.
index.jsView on unpkg · L43This report applies to hardhat-base@2.2.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source passes code obtained from a remote response into a dynamic execution sink.
lib/caller.jsView on unpkg · L2Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/caller.jsView on unpkg · L2The spawned module decodes a concealed remote URL and fetches it with Axios.
lib/caller.jsView on unpkg · L12Importing the main export starts a detached Node process without user interaction.
index.jsView on unpkg · L32Importing the main export starts a detached Node process without user interaction.
index.jsView on unpkg · L43