rollup-plugins-polyfills-rode ===
Importing the CommonJS main entry automatically installs an undeclared external npm package and executes its exported plugin. This creates remote code execution through registry-delivered code in the consumer project.
Source decodes numeric character arrays into a child-process package-runner command and executes it.
dist/index.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkgPackage source references dynamic require/import behavior.
dist/index.jsView on unpkg · L2A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/polyfills.jsView on unpkg · L2Package source references a known benign dynamic code generation pattern.
dist/polyfills.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modules.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/modules.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/es/modules.jsView on unpkgSource decodes numeric character arrays into a child-process package-runner command and executes it.
dist/index.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkgPackage source references dynamic require/import behavior.
dist/index.jsView on unpkg · L2A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/polyfills.jsView on unpkg · L2Package source references a known benign dynamic code generation pattern.
dist/polyfills.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/modules.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/modules.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/es/modules.jsView on unpkg