test
Installing the package triggers collection of local system and account metadata. The data is posted to a fixed external endpoint without user action.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe preinstall hook automatically runs index.js during installation.
package.jsonView on unpkg · L8Source captures command output, transforms it, and includes it in a POST body sent to a literal external destination.
index.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgThis report applies to @cp-shared-14/frontend-ui@6.3.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe preinstall hook automatically runs index.js during installation.
package.jsonView on unpkg · L8Source captures command output, transforms it, and includes it in a POST body sent to a literal external destination.
index.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkg