embedded module for device information collection. Educational and enterprise use.
Importing the package starts a detached background process. That process downloads attacker-controlled JavaScript and executes it with Node module-loading access.
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
init.jsView on unpkg · L1Initialization launches a detached, hidden loader and records its PID.
init.jsView on unpkg · L35Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
loader.jsView on unpkg · L1The loader fetches a remote response from api.npoint.io.
loader.jsView on unpkg · L61Package source references a known benign dynamic code generation pattern.
loader.jsView on unpkg · L75Importing the main entry automatically starts initialization.
index.jsView on unpkg · L12This report applies to @biz44/id44-client@1.1.44.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
init.jsView on unpkg · L1Initialization launches a detached, hidden loader and records its PID.
init.jsView on unpkg · L35Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
loader.jsView on unpkg · L1The loader fetches a remote response from api.npoint.io.
loader.jsView on unpkg · L61Package source references a known benign dynamic code generation pattern.
loader.jsView on unpkg · L75Importing the main entry automatically starts initialization.
index.jsView on unpkg · L12