Security research - dependency confusion test. Contact: security researcher, ref Halodoc VDP.
Installing the package triggers an outbound callback containing the host name. The failure is suppressed, making the callback non-blocking.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpostinstall runs curl automatically during npm installation.
package.jsonView on unpkg · L5Manifest describes the package as a dependency-confusion security test.
package.jsonView on unpkg · L4Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgAn npm script contacts a known out-of-band callback or webhook service.
package.json#scripts.postinstallView on unpkgAn npm script sends host identity through command substitution to a fixed external destination.
package.json#scripts.postinstallView on unpkgThis report applies to @medisend/webview-bridge@0.0.1-security-research.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpostinstall runs curl automatically during npm installation.
package.jsonView on unpkg · L5Manifest describes the package as a dependency-confusion security test.
package.jsonView on unpkg · L4Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgAn npm script contacts a known out-of-band callback or webhook service.
package.json#scripts.postinstallView on unpkgAn npm script sends host identity through command substitution to a fixed external destination.
package.json#scripts.postinstallView on unpkg