When the worker or Android service initializes enabled mail accounts, it transmits account metadata to an unrelated remote logging host. The transmitted log includes email address, IMAP host, and the configured authentication value.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
worker-bundle.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
worker-bundle.jsView on unpkgAccount registration logs account ID, email, IMAP host, and auth value through that logger.
sync-manager.jsView on unpkg · L30Worker initialization registers every enabled account, triggering the logging path.
worker-entry.jsView on unpkg · L151Android bootstrap repeats the same remote logging behavior.
android-bootstrap.jsView on unpkg · L44Source file is highly similar to a previously finalized malicious package; route for source-aware review.
worker-bundle.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
worker-bundle.jsView on unpkgAccount registration logs account ID, email, IMAP host, and auth value through that logger.
sync-manager.jsView on unpkg · L30Worker initialization registers every enabled account, triggering the logging path.
worker-entry.jsView on unpkg · L151Android bootstrap repeats the same remote logging behavior.
android-bootstrap.jsView on unpkg · L44