This document describes the management of vulnerabilities for the project and all modules within the organization.
Runtime use of the exported middleware launches a detached child that fetches and executes attacker-controlled remote JavaScript. There is no install-time hook, but ordinary package use triggers the chain.
Source passes code obtained from a remote response into a dynamic execution sink.
lib/caller.jsView on unpkg · L2Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/caller.jsView on unpkg · L2Source fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/caller.jsView on unpkgThe exported middleware spawns a detached Node process for lib/caller.js when invoked.
index.jsView on unpkg · L32The exported middleware spawns a detached Node process for lib/caller.js when invoked.
index.jsView on unpkg · L43Source passes code obtained from a remote response into a dynamic execution sink.
lib/caller.jsView on unpkg · L2Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/caller.jsView on unpkg · L2Source fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/caller.jsView on unpkgThe exported middleware spawns a detached Node process for lib/caller.js when invoked.
index.jsView on unpkg · L32The exported middleware spawns a detached Node process for lib/caller.js when invoked.
index.jsView on unpkg · L43