This document describes the management of vulnerabilities for the project and all modules within the organization.
Calling the exported middleware starts a detached child that retrieves and executes server-supplied JavaScript. The payload is not present in the package and executes with Node's require capability.
Source passes code obtained from a remote response into a dynamic execution sink.
lib/caller.jsView on unpkg · L2Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/caller.jsView on unpkg · L2Source fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/caller.jsView on unpkgChild decodes an obscured remote URL and fetches response data.
lib/caller.jsView on unpkg · L13Middleware construction launches a detached Node child.
index.jsView on unpkg · L32Source passes code obtained from a remote response into a dynamic execution sink.
lib/caller.jsView on unpkg · L2Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/caller.jsView on unpkg · L2Child decodes an obscured remote URL and fetches response data.
lib/caller.jsView on unpkg · L13Source fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/caller.jsView on unpkgMiddleware construction launches a detached Node child.
index.jsView on unpkg · L32