The Android runtime uploads account configuration to a hard-coded logging host. The serialized IMAP configuration can contain a password.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
worker-entry.tsView on unpkg · L37Source file is highly similar to a previously finalized malicious package; route for source-aware review.
worker-bundle.jsView on unpkgThe Android bootstrap sends verbose logs to a hard-coded third-party host.
android-bootstrap.tsView on unpkg · L55During account setup it serializes the complete IMAP configuration into those logs, which includes the account password.
android-bootstrap.tsView on unpkg · L1541During account setup it serializes the complete IMAP configuration into those logs, which includes the account password.
web-settings.tsView on unpkg · L280This report applies to @bobfrankston/mailx-store-web@0.1.113.
See version security history for other recorded verdicts.
Evidence last updated: .
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
worker-entry.tsView on unpkg · L37Source file is highly similar to a previously finalized malicious package; route for source-aware review.
worker-bundle.jsView on unpkgThe Android bootstrap sends verbose logs to a hard-coded third-party host.
android-bootstrap.tsView on unpkg · L55During account setup it serializes the complete IMAP configuration into those logs, which includes the account password.
android-bootstrap.tsView on unpkg · L1541During account setup it serializes the complete IMAP configuration into those logs, which includes the account password.
web-settings.tsView on unpkg · L280