The Android bootstrap exfiltrates IMAP account configuration to a non-service logging host. This configuration includes mail credentials.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
worker-entry.tsView on unpkg · L37Source file is highly similar to a previously finalized malicious package; route for source-aware review.
worker-bundle.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
worker-bundle.jsView on unpkgAccount normalization retains IMAP and SMTP passwords.
web-settings.jsView on unpkg · L251Account registration logs the complete IMAP configuration by JSON-serializing account.imap.
android-bootstrap.jsView on unpkg · L1513This report applies to @bobfrankston/mailx-store-web@0.1.116.
See version security history for other recorded verdicts.
Evidence last updated: .
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
worker-entry.tsView on unpkg · L37Source file is highly similar to a previously finalized malicious package; route for source-aware review.
worker-bundle.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
worker-bundle.jsView on unpkgAccount normalization retains IMAP and SMTP passwords.
web-settings.jsView on unpkg · L251Account registration logs the complete IMAP configuration by JSON-serializing account.imap.
android-bootstrap.jsView on unpkg · L1513