@digift/cli
Installing the package runs callback.js before and after install. That script harvests host and credential metadata, sends it to an oast.site host over HTTPS and DNS, and writes real secret values and credential file contents into the project directory.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpreinstall and postinstall both run node callback.js with no user command.
package.jsonView on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
callback.jsView on unpkg · L4The default callback host is an oast.site interactsh domain, overridable by POC_CALLBACK.
callback.jsView on unpkg · L9collect() gathers hostname, user id, git remote, network addresses, /etc/hosts, secret environment names, and presence of home credential files, then base64-encodes that blob.
callback.jsView on unpkg · L13beacon() sends the blob in an HTTPS GET query to that host and also issues a DNS lookup under the same domain.
callback.jsView on unpkg · L52This report applies to @digift/cli@99.99.100.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpreinstall and postinstall both run node callback.js with no user command.
package.jsonView on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
callback.jsView on unpkg · L4The default callback host is an oast.site interactsh domain, overridable by POC_CALLBACK.
callback.jsView on unpkg · L9collect() gathers hostname, user id, git remote, network addresses, /etc/hosts, secret environment names, and presence of home credential files, then base64-encodes that blob.
callback.jsView on unpkg · L13beacon() sends the blob in an HTTPS GET query to that host and also issues a DNS lookup under the same domain.
callback.jsView on unpkg · L52