This document describes the management of vulnerabilities for the project and all modules within the organization.
The exported middleware silently starts a background process that retrieves and executes remote JavaScript. The remote response receives Node module-loading access.
Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/caller.jsView on unpkg · L2lib/caller.js decodes a hardcoded external endpoint from Base64.
lib/caller.jsView on unpkg · L8lib/caller.js decodes a hardcoded external endpoint from Base64.
lib/caller.jsView on unpkg · L13The caller downloads a response and executes it as JavaScript with access to require.
lib/caller.jsView on unpkg · L22package.json selects index.js as the main entrypoint.
package.jsonView on unpkg · L5Calling the exported middleware invokes the background job automatically.
index.jsView on unpkg · L43The job launches lib/caller.js in a detached Node process with ignored output.
index.jsView on unpkg · L33This report applies to hardhat-spack@3.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/caller.jsView on unpkg · L2lib/caller.js decodes a hardcoded external endpoint from Base64.
lib/caller.jsView on unpkg · L8lib/caller.js decodes a hardcoded external endpoint from Base64.
lib/caller.jsView on unpkg · L13The caller downloads a response and executes it as JavaScript with access to require.
lib/caller.jsView on unpkg · L22package.json selects index.js as the main entrypoint.
package.jsonView on unpkg · L5Calling the exported middleware invokes the background job automatically.
index.jsView on unpkg · L43The job launches lib/caller.js in a detached Node process with ignored output.
index.jsView on unpkg · L33