Loading npm security reports…
The browser entrypoint contains a credential-harvesting and keylogging payload behind window.__VEIL__.init(). It exfiltrates collected browser and form data to a fixed external webhook while displaying a benign-looking security interface.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
app.jsView on unpkgA manifest entrypoint or package-local install chain reaches a fixed external POST callback.
app.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
app.jsView on unpkgA manifest entrypoint or package-local install chain reaches a fixed external POST callback.
app.jsView on unpkg