A database which has the common knowledge
Calling the exported start method can activate hidden, machine-specific behavior. Separately, processing a user-defined function evaluates its function text as code.
Source decodes a Base64-obscured HTTP endpoint at runtime.
semanticdb.min.jsView on unpkg · L1The only exported startup path is secretly restricted to one machine identifier and a time limit.
semanticdb.min.jsView on unpkg · L1The runtime evaluates a function string taken from a user-defined function object, enabling arbitrary code execution when that data is attacker-controlled.
semanticdb.min.jsView on unpkg · L1The main source is heavily obfuscated and includes dynamic Function-based anti-analysis code.
semanticdb.min.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
semanticdb.min.jsView on unpkg · L1This report applies to semanticdb@0.3.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source decodes a Base64-obscured HTTP endpoint at runtime.
semanticdb.min.jsView on unpkg · L1The only exported startup path is secretly restricted to one machine identifier and a time limit.
semanticdb.min.jsView on unpkg · L1The runtime evaluates a function string taken from a user-defined function object, enabling arbitrary code execution when that data is attacker-controlled.
semanticdb.min.jsView on unpkg · L1The main source is heavily obfuscated and includes dynamic Function-based anti-analysis code.
semanticdb.min.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
semanticdb.min.jsView on unpkg · L1