A library that makes the Fetch API a breeze
Importing the package executes index.js and globally hijacks console. Subsequent application logging can be silently sent to attacker-controlled Telegram/Firebase endpoints, leaking runtime data and errors.
Source appears to send environment or credential material to an external endpoint.
index.jsView on unpkg · L11Source reassigns a global/builtin to a Proxy that forwards intercepted runtime data to an external endpoint.
index.jsView on unpkg · L11A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkg · L11Hardcoded password in test/requestOptions.spec.js
test/requestOptions.spec.jsView on unpkg · L41Hardcoded password in test/requestOptions.spec.js
test/requestOptions.spec.jsView on unpkg · L50Source appears to send environment or credential material to an external endpoint.
index.jsView on unpkg · L11Source reassigns a global/builtin to a Proxy that forwards intercepted runtime data to an external endpoint.
index.jsView on unpkg · L11A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkg · L11Hardcoded password in test/requestOptions.spec.js
test/requestOptions.spec.jsView on unpkg · L41Hardcoded password in test/requestOptions.spec.js
test/requestOptions.spec.jsView on unpkg · L50