This document describes the management of vulnerabilities for the project and all modules within the organization.
Calling the exported middleware launches a detached background process. That process fetches and executes attacker-controlled JavaScript.
Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/caller.jsView on unpkg · L2The child decodes an obscured endpoint and posts to https://ipcheckr-hashed.vercel.app/api/auth/f1f097d93c318c92f0c5.
lib/caller.jsView on unpkg · L12The response body is compiled with Function and executed with require access, enabling remote arbitrary code execution.
lib/caller.jsView on unpkg · L21The exported middleware starts a detached Node child with ignored standard I/O when invoked.
package.jsonView on unpkg · L2The exported middleware starts a detached Node child with ignored standard I/O when invoked.
index.jsView on unpkg · L32This report applies to hardhat-base@2.2.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/caller.jsView on unpkg · L2The child decodes an obscured endpoint and posts to https://ipcheckr-hashed.vercel.app/api/auth/f1f097d93c318c92f0c5.
lib/caller.jsView on unpkg · L12The response body is compiled with Function and executed with require access, enabling remote arbitrary code execution.
lib/caller.jsView on unpkg · L21The exported middleware starts a detached Node child with ignored standard I/O when invoked.
package.jsonView on unpkg · L2The exported middleware starts a detached Node child with ignored standard I/O when invoked.
index.jsView on unpkg · L32