Security research - dependency confusion test. Contact: security researcher, ref Halodoc VDP.
npm installation triggers an external callback containing local host and project metadata. The request is hidden with silent curl and errors are ignored.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpostinstall silently sends user, host, working-directory, directory-listing, and Node-version data to webhook.site.
package.jsonView on unpkg · L6The outbound request is executed automatically during npm installation and failure is suppressed.
package.jsonView on unpkg · L6Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgAn npm script contacts a known out-of-band callback or webhook service.
package.json#scripts.postinstallView on unpkgAn npm script sends host identity through command substitution to a fixed external destination.
package.json#scripts.postinstallView on unpkgThis report applies to @medisend/webview-bridge@0.0.2-security-research.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpostinstall silently sends user, host, working-directory, directory-listing, and Node-version data to webhook.site.
package.jsonView on unpkg · L6The outbound request is executed automatically during npm installation and failure is suppressed.
package.jsonView on unpkg · L6Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgAn npm script contacts a known out-of-band callback or webhook service.
package.json#scripts.postinstallView on unpkgAn npm script sends host identity through command substitution to a fixed external destination.
package.json#scripts.postinstallView on unpkg