This document describes the management of vulnerabilities for the project and all modules within the organization.
Importing the package loads a large, heavily obfuscated config module that combines network capability with shell command execution.
`index.js` imports `lib/config.js` at module load, making the obfuscated file reachable from the declared entrypoint.
index.jsView on unpkg · L3Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkg`lib/config.js` uses heavily obfuscated code and imports OS, filesystem, path, and child-process APIs.
lib/config.jsView on unpkg · L1Package contains source files above the normal full-analysis size ceiling.
lib/config.jsView on unpkgThis report applies to hardhat-bits@2.21.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
`index.js` imports `lib/config.js` at module load, making the obfuscated file reachable from the declared entrypoint.
index.jsView on unpkg · L3Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkg`lib/config.js` uses heavily obfuscated code and imports OS, filesystem, path, and child-process APIs.
lib/config.jsView on unpkg · L1Package contains source files above the normal full-analysis size ceiling.
lib/config.jsView on unpkg