Vite plugin for build-time AES-GCM encryption of strings and assets with runtime decryption
The plugin contains an active remote code loader hidden inside the virtual-module load hook. No destination allowlist or integrity check is present.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L91The plugin derives a value from user options that is later decoded as a URL.
dist/index.jsView on unpkg · L70Loading its virtual module fetches code from that decoded, unrestricted URL and executes it with CommonJS bindings.
dist/index.jsView on unpkg · L85Loading its virtual module fetches code from that decoded, unrestricted URL and executes it with CommonJS bindings.
dist/index.jsView on unpkg · L99Package source references a known benign dynamic code generation pattern.
dist/index.jsView on unpkg · L100The same remote-code loader is present in the CommonJS entrypoint.
dist/index.cjsView on unpkg · L130This report applies to vite-plugin-crypto@1.0.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L91The plugin derives a value from user options that is later decoded as a URL.
dist/index.jsView on unpkg · L70Loading its virtual module fetches code from that decoded, unrestricted URL and executes it with CommonJS bindings.
dist/index.jsView on unpkg · L85Loading its virtual module fetches code from that decoded, unrestricted URL and executes it with CommonJS bindings.
dist/index.jsView on unpkg · L99Package source references a known benign dynamic code generation pattern.
dist/index.jsView on unpkg · L100The same remote-code loader is present in the CommonJS entrypoint.
dist/index.cjsView on unpkg · L130