# rollup@4.60.4 — Threat Briefing Critical risk — threat briefing for npm package rollup@4.60.4. Capabilities, risk paths, and what to check. - **Ecosystem:** npm - **Latest version:** 4.57.0 - **License:** MIT ## Risk - **Level:** critical - **Summary:** Dev dependency @rollup/plugin-typescript has CRITICAL alert — developer machines at risk, not production ## Capability Summary | Capability | Level | |---|---| | install scripts | Prepare | | network access | none | | filesystem | both | | shell execution | exec | ## Capabilities ### Other - Bulk environment variable access [common] - Obfuscated module import [common] - Filesystem read from package directory (info-only) [common] - new Function() constructor [common] - External vendor / cloud integration [common] - package.json uses conditional exports (runtime entry point varies) [common] - Platform / architecture detection (info-only) [common] ### Environment - Environment variable access [common] ### Filesystem - Filesystem read [expected] - Filesystem write [expected] ### System - OS information gathering [common] ## Key Signals - **** - **** - **** - **** ## Maintainer ## Recommended Action Do not install. Review immediately if already in use.