The Android bootstrap exfiltrates account configuration through a hardcoded remote logging endpoint. Serialized IMAP configuration can contain credentials.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
worker-entry.tsView on unpkg · L37Source file is highly similar to a previously finalized malicious package; route for source-aware review.
worker-bundle.jsView on unpkgThe Android runtime sends verbose log text to a hardcoded third-party host.
android-bootstrap.tsView on unpkg · L55Android initialization passes each cloud-loaded account's serialized IMAP settings to that logger.
android-bootstrap.tsView on unpkg · L1541The Android runtime sends verbose log text to a hardcoded third-party host.
android-bootstrap.jsView on unpkg · L45Android initialization passes each cloud-loaded account's serialized IMAP settings to that logger.
android-bootstrap.jsView on unpkg · L1513This report applies to @bobfrankston/mailx-store-web@0.1.118.
See version security history for other recorded verdicts.
Evidence last updated: .
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
worker-entry.tsView on unpkg · L37Source file is highly similar to a previously finalized malicious package; route for source-aware review.
worker-bundle.jsView on unpkgThe Android runtime sends verbose log text to a hardcoded third-party host.
android-bootstrap.tsView on unpkg · L55Android initialization passes each cloud-loaded account's serialized IMAP settings to that logger.
android-bootstrap.tsView on unpkg · L1541The Android runtime sends verbose log text to a hardcoded third-party host.
android-bootstrap.jsView on unpkg · L45Android initialization passes each cloud-loaded account's serialized IMAP settings to that logger.
android-bootstrap.jsView on unpkg · L1513