poc
Importing the browser entry point exfiltrates cookies, page content, and authenticated profile data. Data is posted to a fixed third-party webhook.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
index.jsView on unpkgA manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgThe main entry point sends browser cookies and page HTML to a fixed webhook receiver.
index.jsView on unpkg · L2The main entry point sends browser cookies and page HTML to a fixed webhook receiver.
index.jsView on unpkg · L6It requests the authenticated relative profile endpoint and forwards its response to that receiver.
index.jsView on unpkg · L17The main entry point sends browser cookies and page HTML to a fixed webhook receiver.
index.jsView on unpkg · L14This report applies to @firelordzuka/pulse-poc@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
index.jsView on unpkgA manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgThe main entry point sends browser cookies and page HTML to a fixed webhook receiver.
index.jsView on unpkg · L2The main entry point sends browser cookies and page HTML to a fixed webhook receiver.
index.jsView on unpkg · L6It requests the authenticated relative profile endpoint and forwards its response to that receiver.
index.jsView on unpkg · L17The main entry point sends browser cookies and page HTML to a fixed webhook receiver.
index.jsView on unpkg · L14