Lystech Core contains essentials for lystech apps
npm postinstall mutates the consuming project by adding a persistent GitHub Actions workflow without consent. On repository pushes, that workflow queries GitHub with its token and sends repository identifiers to an external registry.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/lystech-core-provider.umd.jsView on unpkg · L16Package contains a high-severity secret pattern.
dist/lystech-core-provider.umd.jsView on unpkg · L1727A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/lystech-core-provider.umd.jsView on unpkg · L16Google API key in dist/lystech-core-provider.umd.js
dist/lystech-core-provider.umd.jsView on unpkg · L1727Source appears to send environment or credential material to an external endpoint.
dist/lystech-core-provider.es.jsView on unpkg · L44Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/attach.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/check-pwa.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/postinstall.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/setup-registry.cjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L28Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L28A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/lystech-core-provider.umd.jsView on unpkg · L16Package contains a high-severity secret pattern.
dist/lystech-core-provider.umd.jsView on unpkg · L1727Source appears to send environment or credential material to an external endpoint.
dist/lystech-core-provider.es.jsView on unpkg · L44Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/attach.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/check-pwa.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/postinstall.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/setup-registry.cjsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/lystech-core-provider.umd.jsView on unpkg · L16Google API key in dist/lystech-core-provider.umd.js
dist/lystech-core-provider.umd.jsView on unpkg · L1727