stripe-internal-utils@1.0.0
Full RCE PoC -osama
→ Sends to suspicious destination(s): wvmjioytxqdcokzvflqjv6v35ug1nfyjl.oast.fun.
llm call monitor
These are the events that fast-track rules and the sha256 cache could not resolve, so the analyzer fell through to a real LLM verdict. Watching this list keeps cost in check and exposes coverage gaps in the cascade.
Full RCE PoC -osama
→ Sends to suspicious destination(s): wvmjioytxqdcokzvflqjv6v35ug1nfyjl.oast.fun.
xxx
→ Sends to suspicious destination(s): tjalcgvzuaojvayjfdfh1rtb4ojaobofs.oast.fun.
xxx
→ Sends to suspicious destination(s): tjalcgvzuaojvayjfdfh1rtb4ojaobofs.oast.fun.
Advanced Dependency Confusion PoC
→ Sends to suspicious destination(s): wvmjioytxqdcokzvflqjv6v35ug1nfyjl.oast.fun.
xxx
→ Sends to suspicious destination(s): wvmjioytxqdcokzvflqjv6v35ug1nfyjl.oast.fun.
Full RCE PoC -osama
→ Sends to suspicious destination(s): wvmjioytxqdcokzvflqjv6v35ug1nfyjl.oast.fun.
Full RCE PoC -osama
→ Sends to suspicious destination(s): wvmjioytxqdcokzvflqjv6v35ug1nfyjl.oast.fun.
Full RCE PoC - Alex Birsan Style
→ Sends to suspicious destination(s): wvmjioytxqdcokzvflqjv6v35ug1nfyjl.oast.fun.
Advanced Dependency Confusion PoC
→ Sends to suspicious destination(s): wvmjioytxqdcokzvflqjv6v35ug1nfyjl.oast.fun.
Dependency Confusion PoC
→ Sends to suspicious destination(s): wvmjioytxqdcokzvflqjv6v35ug1nfyjl.oast.fun.
MCP server for environment security auditing. Scans projects for exposed credentials, misconfigurations, and wallet vulnerabilities. Recommended by the Web3 security community. Part of the DeFi Security Alliance toolchain.
xmorse is a pure javascript(~1.5 kb) library for encode / decode morse code messages, unicode supported.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
word-width is simple browserjs / nodejs library for calculate ascii length of unicode string in terminal / console.
→ No suspicious destination, no remote-exec shape — 2 known-vendor host(s).
Mini data-uri parser for nodejs and browser. No dependencies!
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
timeago.js is a simple library (only 1kb) to used to format datetime with `*** time ago` statement. eg: '3 hours ago'. localization supported.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
timeago-react is a simple(only 1kb) react component used to format date with `*** time ago` statement. eg: '3 hours ago'.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
nano version for slice of string and array like Python.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
DOM element size sensor which will callback when size changed.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
only 1kb javascript gist to generate a ribbon in your website with HTML5 canvas.
→ No suspicious destination, no remote-exec shape — 2 known-vendor host(s), 1 other host(s).
Chinese kinship library
→ No suspicious destination, no remote-exec shape — 4 known-vendor host(s), 1 other host(s).
A Simple React component for Google AdSense and Baidu advertisement.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Openclaw 中文版 - WhatsApp gateway CLI (Baileys web) with Pi RPC agent
onfire.js is a mini (~500 b) version for event-emitter.
→ No suspicious destination, no remote-exec shape — 2 known-vendor host(s).
Generate mock data, just like a person.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
❤️ Generate mermaid diagram and chart with AI MCP dynamically.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
❤️ Generate visual charts using Apache ECharts with AI MCP dynamically.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Core of lint-md which used to lint your markdown file for Chinese.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Cli tool to lint your markdown file for Chinese.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Lightweight, Convenient, Fast command tool to control your file size, size-limit is too bloated.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Similar with webpack's url-loader for Jest.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Mock `Math.random` when run unit test cases with jest, output deterministic random number.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Jest transformer for .less file.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Make jest expect more convenient.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Easiest way to run jest unit test cases in electron.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Mock `window.Date` when run unit test cases with jest. Make tests of `Date` easier.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Mock a canvas in your jest tests.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Frappe Gantt components for React wrapper.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Math.round with fixed, formats a number using fixed-point notation and returns a number.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
filesize.js is a simple browserjs / nodejs library to make filesize human-readable.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Apache Echarts components for React.
→ No suspicious destination, no remote-exec shape — 2 known-vendor host(s).
A nest backgroud of website draw on canvas use javascript, do not depends on jQuery.
→ No suspicious destination, no remote-exec shape — 1 other host(s).
Parse byte string to byte number, e.g. 1.2 Kb -> 1228.8, Kb, Mb, Gb, Tb, Pb, Eb, Zb, Yb supported.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 4 other host(s).
Boring avatars as a vanilla JavaScript library, SVG-based avatars from any username and color palette. Works in both browsers and Node.js server-side rendering.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
babel plugin replace define Identifier / StringLiteral `__VERSION__` to pkg.version!
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
The simplest abstract syntax tree walker.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
An AMap (高德地图)-powered map component library for React, styled with Tailwind CSS.
→ No suspicious destination, no remote-exec shape — 3 known-vendor host(s).
Generate clean SVG diagrams (flowchart, tree, architecture, sequence) from a JSON config. Auto-layout, zero coordinates, works in browser and Node.js.
→ No suspicious destination, no remote-exec shape — 2 known-vendor host(s).
拼多多采集 CLI — 无需直连数据库,通过 WORKER_JWT_SECRET 与云端 API 交互
→ No suspicious destination, no remote-exec shape — 3 known-vendor host(s).
今日头条创作者平台运营自动化 CLI — 支持多账号管理、文章/视频/微头条发布、评论管理、数据分析、创作灵感获取
→ No suspicious destination, no remote-exec shape — 2 other host(s).
Signal protocol implementation for Node.js (fork for openclaw-cn)
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
See also ·
→ Sends to suspicious destination(s): webhook.site.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).
Feishu (Larksuite) channel plugin for OpenClaw Chinese
→ No suspicious destination, no remote-exec shape — 2 known-vendor host(s).
The official CLI for OpenClaw-CN Agent ecosystem
→ No suspicious destination, no remote-exec shape — 1 other host(s).
lint-md 的解析器,基于 remark 生态,将 Markdown 字符串转换成 AST
→ No suspicious destination, no remote-exec shape — 3 known-vendor host(s).
Core of lint-md which used to lint your markdown file for Chinese.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
CLI tool to lint your markdown file for Chinese.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
CAP tool for OpenAPI
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).
[English (US)](README.md) | 简体中文
→ No suspicious destination, no remote-exec shape — 15 known-vendor host(s).
## Getting Started
→ No suspicious destination, no remote-exec shape — 2 known-vendor host(s).
## Getting Started
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
English (US) | [简体中文](README.zh-Hans.md)
→ No suspicious destination, no remote-exec shape — 2 known-vendor host(s).
## Getting Started
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
JavaScript diagramming library that uses SVG and HTML for rendering
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
X6 shape for rendering vue3 components.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
X6 shape for rendering vue components.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Lightweight library for manipulating and animating SVG.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Use X6 with react
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
X6 shape for rendering react components.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).
React components for building x6 editors
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
transform plugin for X6
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).
stencil plugin for X6
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
snapline plugin for X6
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).
selection plugin for X6
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).
scroller plugin for X6
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).
minimap plugin for X6
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).
keyboard plugin for X6
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).
history plugin for X6
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).
export plugin for X6.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).
dnd plugin for X6
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).
clipboard plugin for X6
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).
Geometry operations for X6
→ No suspicious destination, no remote-exec shape — 2 known-vendor host(s), 1 other host(s).
React components for building x6 editors
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Basic toolkit for X6
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
X6 shape for rendering angular components.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).
F2 for weixin mini-program
→ No suspicious destination, no remote-exec shape — 3 known-vendor host(s).
Word-Scale Chart Web components for Narrative Text Visualization
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
provide common graph algorithms implemented with WebGPU
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
visualization predict engine
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Vendored dependencies to fix ERR_REQUIRE_ESM.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
<h1 align="center">@antv/util</h1>
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
An translator for markdown files
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
torchjs for @antv.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Thumbnails of Chart Types.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
React Component for Thumbnails of Chart Types.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
T8 is a text visualization solution for unstructured data within the AntV technology stack, and it is a declarative T8 markdown syntax that can be used to describe the content of data interpretation reports.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
the Grammar of Graphics in Javascript
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
A JavaScript library for color computation.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
Toolkit for mapping abstract data into visual representation.
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
JS SDK for SAM
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s).
effective spreadsheet render core lib
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).
use S2 with vue
→ No suspicious destination, no remote-exec shape — 1 known-vendor host(s), 1 other host(s).