This document describes the management of vulnerabilities for the project and all modules within the organization.
Calling the exported middleware silently launches lib/caller.js detached. That child fetches attacker-controlled code from an obscured endpoint and executes it locally.
Source passes code obtained from a remote response into a dynamic execution sink.
lib/caller.jsView on unpkg · L2Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/caller.jsView on unpkg · L2Source fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/caller.jsView on unpkgChild decodes an obscured remote URL and request header.
lib/caller.jsView on unpkg · L12Source passes code obtained from a remote response into a dynamic execution sink.
lib/caller.jsView on unpkg · L2Source decodes a Base64-obscured HTTP endpoint at runtime.
lib/caller.jsView on unpkg · L2Source fingerprint signature matches a known malicious package signature; route for source-aware review.
lib/caller.jsView on unpkgChild decodes an obscured remote URL and request header.
lib/caller.jsView on unpkg · L12