- Created
- 9 years ago
- Last commit
- 5 days ago
- Latest release
- v67.20.02 weeks ago
Security Findings
13Hardcoded C2 with exfil/exec behavior
MaliciousScannerContacts a hardcoded public IP paired with download/eval/sensitive-access/upload
pull_request_target with secrets
MaliciousLineage[.github/workflows/docOnlyAutoMerge.yml] pull_request_target with secrets
Suspicious outbound hosts7×
SuspiciousScannerOutbound URLs to non-allowlisted host(s): cve.mitre.org, datatracker.ietf.org, json-schema.org, man7.org, nvlpubs.nist.gov, soap.sforce.com, tools.ietf.org, www.cl.cam.ac.uk
Outbound URLs to non-allowlisted host(s): chromedevtools.github.io, datatracker.ietf.org, docs.libuv.org, fetch.spec.whatwg.org, http2.github.io, linux.die.net, man7.org, qvis.quictools.info
Outbound URLs to non-allowlisted host(s): [fe80:0:0:0:0:0:0:1], [fe80::1], bmeck.github.io, chromedevtools.github.io, cve.mitre.org, developer.chrome.com, dzone.com, es5.github.io
Outbound URLs to non-allowlisted host(s): registry.yarnpkg.com, soap.sforce.com, www.ecma-international.org
Outbound URLs to non-allowlisted host(s): instancename.lightning.force.com, mydomainname.lightning.force.com, mydomainname.my.site.com, soap.sforce.com, www.nist.gov, www.oasis-open.org
Outbound URLs to non-allowlisted host(s): soap.sforce.com
Outbound URLs to non-allowlisted host(s): 794testsite.my.site.com, breeze.aimon.applicationinsights.io, json-schema.org, soap.sforce.com
Coverage evasion (executable content over cap)
SuspiciousScanner2667 executable file(s) totalling 3062413 bytes exceeded the bundle or per-file ceiling and were dropped or head-truncated (80.35% of code-bearing bytes reached the rules)
Install-lifecycle script shipped
SuspiciousScannerpackage.json preinstall script is shipped (inert on VSIX install but a build-hygiene / dev-tooling tell): node ../../scripts/require-root-install.js