Lystech Core contains essentials for lystech apps
Install-time code modifies a consumer repository by creating a GitHub Actions workflow. That workflow persists across pushes and reports repository metadata to a third-party service.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource appears to send environment or credential material to an external endpoint.
dist/lystech-core-provider.umd.jsView on unpkg · L16A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/lystech-core-provider.umd.jsView on unpkg · L16Package contains a high-severity secret pattern.
dist/lystech-core-provider.umd.jsView on unpkg · L1727Google API key in dist/lystech-core-provider.umd.js
dist/lystech-core-provider.umd.jsView on unpkg · L1727Package contains source files above the static scanner size ceiling.
dist/lystech-core-provider.es.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/attach.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/attach.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/check-pwa.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/postinstall.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/setup-registry.cjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L28Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L28Source appears to send environment or credential material to an external endpoint.
dist/lystech-core-provider.umd.jsView on unpkg · L16A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
Package contains source files above the static scanner size ceiling.
dist/lystech-core-provider.es.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/attach.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/attach.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/check-pwa.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/postinstall.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/setup-registry.cjsView on unpkgPackage contains a high-severity secret pattern.
dist/lystech-core-provider.umd.jsView on unpkg · L1727Google API key in dist/lystech-core-provider.umd.js
dist/lystech-core-provider.umd.jsView on unpkg · L1727