stripe-internal-utils@1.0.0
Full RCE PoC -osama
→ 의심 전송지로 발송: wvmjioytxqdcokzvflqjv6v35ug1nfyjl.oast.fun.
// System reconnaissance
패턴: reads-env-vars
Packages whose static analysis matched this pattern. See the per-package detail pages for the offending code excerpt.
25개 패키지에 이 패턴이 매칭됨 (총 publish 이벤트 31건을 publisher+name 기준으로 묶음). 최신순.
Full RCE PoC -osama
→ 의심 전송지로 발송: wvmjioytxqdcokzvflqjv6v35ug1nfyjl.oast.fun.
xxx
→ 의심 전송지로 발송: tjalcgvzuaojvayjfdfh1rtb4ojaobofs.oast.fun.
Full RCE PoC - Alex Birsan Style
→ 의심 전송지로 발송: wvmjioytxqdcokzvflqjv6v35ug1nfyjl.oast.fun.
CI/CD Security Posture Scanner — scores AWS, Terraform, CloudFormation, GitHub Actions, GitLab CI, Azure DevOps, Bitbucket Pipelines, Jenkins, CircleCI, Google Cloud Build, Buildkite, Drone CI, Tekton, Argo Workflows, Dockerfile, Kubernetes manifests, Helm charts, OCI image manifests, SCM repo posture (GitHub / GitLab / Bitbucket), npm and pypi dependency files against OWASP Top 10 CI/CD Risks and 14 other compliance frameworks
→ Worm self-propagation: package reads .npmrc _authToken AND invokes npm publish in install-path code. Shai-Hulud-class shape — no legitimate package re-publishes OTHER packages from the user's machine.
Openclaw 中文版 - WhatsApp gateway CLI (Baileys web) with Pi RPC agent
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s), 1 other host(s).
Easiest way to run jest unit test cases in electron.
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
Apache Echarts components for React.
→ 의심 전송지 없음, 원격 실행 형태 없음 — 2 known-vendor host(s).
The official CLI for OpenClaw-CN Agent ecosystem
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 other host(s).
torchjs for @antv.
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
effective spreadsheet render core lib
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s), 1 other host(s).
use S2 with react
React component of interactive narrative text
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
React component of narrative text editor
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
MCP Server for AntV visualization libraries development, which provides documentation context and examples for visualization developers.
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
Standard Tooling for location insight assets
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
L7-React 已全面 升级为 LarkMap,不在进行维护 。 LarkMap 空间数据可视分析组件库
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s), 1 other host(s).
A drawing package for L7
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
Yet another JS code coverage tool that computes statement, line, function and branch coverage with module loader hooks to transparently add coverage when running tests. Supports all JS coverage use cases including unit tests, server side functional tests
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
Components for graphin
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
Scaffolding Your Extension for G6
→ 의심 전송지 없음, 원격 실행 형태 없음 — 4 known-vendor host(s).
Select a one-, two-dimensional or irregular region using the mouse.
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
Charts for mobile visualization.
→ 의심 전송지 없음, 원격 실행 형태 없음 — 6 known-vendor host(s), 1 other host(s).
FEngine 是 AntV F 系列可视化引擎的底层渲染引擎,为移动端提供了一套完整的渲染、事件、动画能力,能方便的构建可视化 UI
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
在线 Demo 地址: https://antv.vision/DipperMap/demo
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s), 1 other host(s).