An unusual exported subpath executes setup.js on import and drops a staged Deno handler. That handler is designed to collect sensitive local files and disclose them to its HTTP caller.
setup.js embeds a Deno HTTP handler that reads /readflag, /flagserver, /app/backdoor.tsx, and /entrypoint.sh.
app/backdoor.tsxView on unpkgImporting the exported ./package.json subpath runs setup.js and writes the handler to /tmp/h.tsx.
package.jsonView on unpkgThis report applies to z-deno-truth-ya1t4m@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
setup.js embeds a Deno HTTP handler that reads /readflag, /flagserver, /app/backdoor.tsx, and /entrypoint.sh.
app/backdoor.tsxView on unpkgImporting the exported ./package.json subpath runs setup.js and writes the handler to /tmp/h.tsx.
package.jsonView on unpkg