POS network stability helper module
The package presents itself as a point-of-sale stability helper, but its entrypoint decodes a hidden endpoint and token, downloads a fault document, and uses that document to fabricate network failures. A non-empty remote whitelist replaces the local list that otherwise skips payment and login paths.
Source decodes a Base64-obscured HTTP endpoint at runtime.
dist/RemoteConfig.jsView on unpkg · L1RemoteConfig hides its service URL and access token as base64 and decodes them at runtime before any request.
dist/RemoteConfig.jsView on unpkg · L1After init, it GETs that decoded host with the token, caches the JSON body, and passes i.config into the fault injector.
dist/RemoteConfig.jsView on unpkg · L1shouldFail uses that remote document to randomly throw fabricated timeout or server errors, and a non-empty remote whitelist replaces the built-in payment-path list.
dist/FaultInjector.jsView on unpkg · L1shouldFail uses that remote document to randomly throw fabricated timeout or server errors, and a non-empty remote whitelist replaces the built-in payment-path list.
dist/whitelist.jsView on unpkg · L1dist/index.js exports the live remoteConfig and faultInjector singletons as the package entrypoint.
dist/index.jsView on unpkg · L1After init, it GETs that decoded host with the token, caches the JSON body, and passes i.config into the fault injector.
dist/types.jsView on unpkg · L1This report applies to network-stab--helper@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source decodes a Base64-obscured HTTP endpoint at runtime.
dist/RemoteConfig.jsView on unpkg · L1RemoteConfig hides its service URL and access token as base64 and decodes them at runtime before any request.
dist/RemoteConfig.jsView on unpkg · L1After init, it GETs that decoded host with the token, caches the JSON body, and passes i.config into the fault injector.
dist/RemoteConfig.jsView on unpkg · L1shouldFail uses that remote document to randomly throw fabricated timeout or server errors, and a non-empty remote whitelist replaces the built-in payment-path list.
dist/FaultInjector.jsView on unpkg · L1shouldFail uses that remote document to randomly throw fabricated timeout or server errors, and a non-empty remote whitelist replaces the built-in payment-path list.
dist/whitelist.jsView on unpkg · L1dist/index.js exports the live remoteConfig and faultInjector singletons as the package entrypoint.
dist/index.jsView on unpkg · L1After init, it GETs that decoded host with the token, caches the JSON body, and passes i.config into the fault injector.
dist/types.jsView on unpkg · L1