This document describes the management of vulnerabilities for the project and all modules within the organization.
Importing the package loads an opaque, obfuscated payload before the exported middleware is used. The payload dynamically decodes behavior and includes filesystem and network-capable logic.
Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/tools.jsView on unpkgSource downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/tools.jsView on unpkg