Local-first email client with IMAP sync and standalone native app
On Android startup, the bundled client transmits account diagnostic data to an unrelated remote logging host. The transmitted IMAP configuration can contain a password.
A newly added or changed runtime dependency can resolve to an independently confirmed malicious package version.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
bin/build-bundles.mjsView on unpkg · L31Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/build-bundles.mjsView on unpkg · L5Package source invokes a package manager install command at runtime.
bin/mailx.jsView on unpkg · L707Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/mailx.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
client/app.bundle.jsView on unpkg · L11966Package source references dynamic require/import behavior.
bin/lean-accounts.jsView on unpkg · L136Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
packages/mailx-store-web/worker-entry.tsView on unpkg · L37A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/share-target.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/mailx.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/build-rmfmailto-exe.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/build-rmfshare-exe.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/share-target.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/share-target.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/android-bootstrap.bundle.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/lib/local-service.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/paste-markdown.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/paste-markdown.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck-core.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck-core.tsView on unpkgPackage source references weak cryptographic algorithms.
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L32Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L32A newly added or changed runtime dependency can resolve to an independently confirmed malicious package version.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
client/app.bundle.jsView on unpkg · L11966A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/share-target.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/mailx.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/build-rmfmailto-exe.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/build-rmfshare-exe.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/share-target.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/share-target.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/android-bootstrap.bundle.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/lib/local-service.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/paste-markdown.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/paste-markdown.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck-core.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck-core.tsView on unpkgPackage source references weak cryptographic algorithms.
bin/build-bundles.mjsView on unpkg · L5Package source references child process execution.
bin/build-bundles.mjsView on unpkg · L31Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/build-bundles.mjsView on unpkg · L5Package source invokes a package manager install command at runtime.
bin/mailx.jsView on unpkg · L707Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/mailx.jsView on unpkgPackage source references dynamic require/import behavior.
bin/lean-accounts.jsView on unpkg · L136Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
packages/mailx-store-web/worker-entry.tsView on unpkg · L37