embedded module for device information collection. Educational and enterprise use.
On package import, it starts a detached loader. The loader retrieves attacker-controlled code from a remote endpoint and executes it in the consumer's Node process context.
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
init.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
loader.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
loader.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
loader.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
loader.jsView on unpkg · L75Importing the package immediately calls its initializer.
index.jsView on unpkg · L12This report applies to @biz44/id99-client@1.1.100.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
init.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
loader.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
loader.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
loader.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
loader.jsView on unpkg · L75Importing the package immediately calls its initializer.
index.jsView on unpkg · L12