Authorized security research placeholder - dependency confusion proof-of-concept. Not the real package. Will be unpublished after triage.
Package installation automatically sends identifying host and project-location metadata to external collectors. The transfer occurs without an explicit user command or consent.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstallation automatically runs a preinstall script.
package.jsonView on unpkg · L6Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe script collects the local hostname, username, current directory, installation path, and npm metadata.
preinstall.jsView on unpkg · L39It encodes the hostname and username into a DNS lookup to an external OAST host.
preinstall.jsView on unpkg · L60It POSTs the collected JSON to an external domain and a raw IP address.
preinstall.jsView on unpkg · L73Comments and README text assert benign security research, which is reviewer-directed self-justification rather than consent.
README.mdView on unpkg · L11This report applies to @caliperx2/components@0.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstallation automatically runs a preinstall script.
package.jsonView on unpkg · L6Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe script collects the local hostname, username, current directory, installation path, and npm metadata.
preinstall.jsView on unpkg · L39It encodes the hostname and username into a DNS lookup to an external OAST host.
preinstall.jsView on unpkg · L60It POSTs the collected JSON to an external domain and a raw IP address.
preinstall.jsView on unpkg · L73Comments and README text assert benign security research, which is reviewer-directed self-justification rather than consent.
README.mdView on unpkg · L11