This document describes the management of vulnerabilities for the project and all modules within the organization.
Importing the package loads a 4 MB obfuscated payload. It gathers host metadata, sends it through axios to an encoded endpoint, and includes process-execution primitives.
Source downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkglib/config.js imports os/fs and execSync/spawn in top-level code.
lib/config.jsView on unpkg · L1Payload collects host, OS, username, message, data, and timestamp.
lib/config.jsView on unpkg · L1Source fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/tools.jsView on unpkgSource downloads or fetches remote code and executes it.
lib/config.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
lib/config.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
lib/config.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/tools.jsView on unpkglib/config.js imports os/fs and execSync/spawn in top-level code.
lib/config.jsView on unpkg · L1Payload collects host, OS, username, message, data, and timestamp.
lib/config.jsView on unpkg · L1