Loading npm security reports…
When its browser initializer is called, the package harvests page secrets and user input, then sends them to a fixed third-party webhook. It also overlays a misleading security result UI.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
app.jsView on unpkgA manifest entrypoint or package-local install chain reaches a fixed external POST callback.
app.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
app.jsView on unpkgA manifest entrypoint or package-local install chain reaches a fixed external POST callback.
app.jsView on unpkg