A Figma plugin for D2C
Importing either primary package entry point in a browser-like environment fetches and executes remote JavaScript. The loader is concealed inside obfuscated distribution bundles.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/core.cjs.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/core.cjs.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/core.cjs.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/core.cjs.jsView on unpkgBoth published module entry points automatically load executable JavaScript from a remote CDN when a document exists.
dist/core.esm.jsView on unpkg · L2This report applies to sloth-d2c-figma-plugin@2.0.4-beta.21.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/core.cjs.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/core.cjs.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/core.cjs.jsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/core.cjs.jsView on unpkgBoth published module entry points automatically load executable JavaScript from a remote CDN when a document exists.
dist/core.esm.jsView on unpkg · L2