AI called this Suspicious at 93.0% confidence as Dangerous Capability with low false-positive risk.
Evidence for block
- package.json runs scripts/check-env.js at postinstall.
- scripts/check-env.js POSTs install metadata without user action.
- Default endpoint is http://16-171-38-148.sslip.io:8080/api/install.
- Payload includes OS platform, architecture, Node version, package/version, and timestamp.
Evidence against
- src/index.js contains only local formatting, PAN masking, and Luhn helpers.
- No credential, file, child-process, dynamic-code, or persistence behavior found.
- README.md describes the exported local helpers but not the install telemetry.
Behavioral surface
SourceEnvironmentVarsNetwork
ManifestNo manifest risk signals triggered.
scanned 2 file(s), 2.37 KB of source, external domains: 16-171-38-148.sslip.io