CLI tool for managing iptables port forwarding through Tailscale tunnels
Installation fetches an unpinned latest-release binary, accepts redirects, writes it into the package, and executes it. The downloaded executable is not part of the reviewed package or integrity-verified.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgnpm automatically runs the installer after installation.
package.jsonView on unpkg · L33Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/install.jsView on unpkgThe installer requests the repository's latest GitHub release rather than a version-pinned artifact.
scripts/install.jsView on unpkg · L34It follows redirect targets and writes the remotely supplied asset without an integrity check.
scripts/install.jsView on unpkg · L67It marks that asset executable and runs it during installation.
scripts/install.jsView on unpkg · L121This report applies to @h3nr1-d14z/nat-gate@2.3.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L34Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L34npm automatically runs the installer after installation.
package.jsonView on unpkg · L33The installer requests the repository's latest GitHub release rather than a version-pinned artifact.
scripts/install.jsView on unpkg · L34It follows redirect targets and writes the remotely supplied asset without an integrity check.
scripts/install.jsView on unpkg · L67It marks that asset executable and runs it during installation.
scripts/install.jsView on unpkg · L121Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/install.jsView on unpkg