The Android bootstrap exfiltrates IMAP configuration, including a password when present, through a silent logging request. It activates during account setup after a consumer calls the exported Android initializer.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
worker-bundle.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
worker-bundle.jsView on unpkgAndroid bootstrap silently sends verbose log text to an unrelated remote host.
android-bootstrap.tsView on unpkg · L54The credential-bearing log runs while Android account setup processes cloud accounts.
android-bootstrap.tsView on unpkg · L1525The credential-bearing log runs while Android account setup processes cloud accounts.
android-bootstrap.tsView on unpkg · L1386Account normalization places the account password in the serialized IMAP configuration.
web-settings.tsView on unpkg · L280Source file is highly similar to a previously finalized malicious package; route for source-aware review.
worker-bundle.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
worker-bundle.jsView on unpkgAndroid bootstrap silently sends verbose log text to an unrelated remote host.
android-bootstrap.tsView on unpkg · L54The credential-bearing log runs while Android account setup processes cloud accounts.
android-bootstrap.tsView on unpkg · L1386The credential-bearing log runs while Android account setup processes cloud accounts.
android-bootstrap.tsView on unpkg · L1525Account normalization places the account password in the serialized IMAP configuration.
web-settings.tsView on unpkg · L280