chrome-devtools
Audited by Socket on Sep 14, 2026
3 alerts found:
Anomalyx2SecurityNo clear malicious behavior or supply-chain attack is evident. The code is a conventional Puppeteer browser manager. Security review is warranted because it disables Chromium sandboxing, trusts endpoint URLs and a local endpoint file, forwards arbitrary launch arguments, and exposes stack traces on errors. These are deployment and input-validation risks rather than evidence of malware.
The code appears to be a legitimate persistent Puppeteer browser launcher, not malware. It contains security risks: disabling the Chrome sandbox, exposing an unauthenticated remote-debugging port, and storing/printing the WebSocket control endpoint. Use should be limited to a trusted local environment, with the debugging port bound or protected and untrusted navigation treated cautiously.
High-risk design due to a direct `eval` of user-supplied code inside page.evaluate, combined with optional navigation to a user-controlled URL before execution. While the fragment alone does not prove malicious payloads, it functions as a general-purpose browser-based code execution and result-return harness, making data leakage/exploitation highly plausible if used with untrusted inputs.