Local-first email client with IMAP sync and standalone native app
When the Android mail client initializes, verbose logging sends account email and the full IMAP settings object, which can contain a password, to the author's logging host in a URL path. The request is silent and not gated by a user flag.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
bin/build-bundles.mjsView on unpkg · L31Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/build-bundles.mjsView on unpkg · L5Package source references weak cryptographic algorithms.
bin/build-bundles.mjsView on unpkg · L5Package source invokes a package manager install command at runtime.
bin/mailx.jsView on unpkg · L707Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/mailx.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
client/app.bundle.jsView on unpkg · L12366Package source references dynamic require/import behavior.
bin/lean-accounts.jsView on unpkg · L136Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
packages/mailx-store-web/worker-entry.tsView on unpkg · L37A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/share-target.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/mailx.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/build-rmfmailto-exe.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/build-rmfshare-exe.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/share-target.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/share-target.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/android-bootstrap.bundle.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/lib/local-service.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck-core.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck-core.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck.tsView on unpkgThis report applies to @bobfrankston/rmfmail@1.2.345.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L32Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L32Package source references a known benign dynamic code generation pattern.
client/app.bundle.jsView on unpkg · L12366A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/share-target.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/mailx.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/build-rmfmailto-exe.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/build-rmfshare-exe.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/share-target.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/share-target.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/android-bootstrap.bundle.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/lib/local-service.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck-core.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck-core.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
client/compose/spellcheck.tsView on unpkgPackage source references weak cryptographic algorithms.
bin/build-bundles.mjsView on unpkg · L5Package source references child process execution.
bin/build-bundles.mjsView on unpkg · L31Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/build-bundles.mjsView on unpkg · L5Package source invokes a package manager install command at runtime.
bin/mailx.jsView on unpkg · L707Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/mailx.jsView on unpkgPackage source references dynamic require/import behavior.
bin/lean-accounts.jsView on unpkg · L136Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
packages/mailx-store-web/worker-entry.tsView on unpkg · L37