Lystech Core contains essentials for lystech apps
Installing the package changes the consuming repository by adding a GitHub Actions workflow. On later pushes, that workflow collects repository identity data and registers it with an external service.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource appears to send environment or credential material to an external endpoint.
dist/lystech-core-provider.umd.jsView on unpkg · L16A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/lystech-core-provider.umd.jsView on unpkg · L16Package contains a high-severity secret pattern.
dist/lystech-core-provider.umd.jsView on unpkg · L1700A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/lystech-core-provider.umd.jsView on unpkg · L16Google API key in dist/lystech-core-provider.umd.js
dist/lystech-core-provider.umd.jsView on unpkg · L1700Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/attach.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/check-pwa.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/postinstall.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/setup-registry.cjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L28Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L28Source appears to send environment or credential material to an external endpoint.
dist/lystech-core-provider.umd.jsView on unpkg · L16A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/attach.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/check-pwa.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/postinstall.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/setup-registry.cjsView on unpkgPackage contains a high-severity secret pattern.
dist/lystech-core-provider.umd.jsView on unpkg · L1700A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/lystech-core-provider.umd.jsView on unpkg · L16Google API key in dist/lystech-core-provider.umd.js
dist/lystech-core-provider.umd.jsView on unpkg · L1700