Local-first email client with IMAP sync and standalone native app
Android startup exfiltrates verbose account diagnostics to a hard-coded third-party host. The logged IMAP object can include the account password.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/mailx.jsView on unpkg · L53Package source invokes a package manager install command at runtime.
bin/mailx.jsView on unpkg · L2539Source writes installer persistence such as shell profile or service configuration.
bin/mailx.jsView on unpkg · L53Package source references a known benign dynamic code generation pattern.
client/app.bundle.jsView on unpkg · L10321Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
bin/lean-accounts.jsView on unpkg · L137Package source references dynamic require/import behavior.
bin/lean-accounts.jsView on unpkg · L136Package source references weak cryptographic algorithms.
bin/build-bundles.mjsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/build-rmfmailto-exe.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/mailx-store-web/worker-bundle.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck-core.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck-core.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L34Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L34Package source references weak cryptographic algorithms.
bin/build-bundles.mjsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/build-rmfmailto-exe.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/mailx-store-web/worker-bundle.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck-core.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck-core.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
bin/mailx.jsView on unpkg · L53Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/mailx.jsView on unpkg · L53Package source invokes a package manager install command at runtime.
bin/mailx.jsView on unpkg · L2539Package source references a known benign dynamic code generation pattern.
client/app.bundle.jsView on unpkg · L10321Package source references dynamic require/import behavior.
bin/lean-accounts.jsView on unpkg · L136Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
bin/lean-accounts.jsView on unpkg · L137