AI called this Suspicious at 91.0% confidence as Unknown with low false-positive risk.
Evidence for block
- package.json runs scripts/check-env.js at postinstall.
- scripts/check-env.js POSTs install metadata to an undeclared external host.
- The outbound telemetry is not documented in README.md.
Evidence against
- src/index.js contains only local formatting, PAN masking, and Luhn validation.
- Lifecycle script sends package name/version, platform, architecture, Node version, and timestamp only.
- No file harvesting, credential reads, shell execution, payload loading, or config writes found.
Behavioral surface
SourceEnvironmentVarsNetwork
ManifestNo manifest risk signals triggered.
scanned 2 file(s), 2.37 KB of source, external domains: 16-171-38-148.sslip.io