Loading npm security reports…
On Android initialization, account configuration including IMAP credentials can be transmitted to an unrelated logging host. This is a concrete credential-exfiltration path.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
worker-bundle.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
worker-bundle.jsView on unpkg