Authorized dep-confusion canary. H1 program verily_life_sciences, report #<ID>. Contact: nimbusedge@wearehackerone.com
Installing the package automatically opens an interactive Bash connection to a remote host and performs an HTTP POST. This is a concrete install-time remote shell and outbound network action.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe automatic preinstall hook launches interactive Bash with standard input and output redirected to a remote TCP socket.
package.jsonView on unpkg · L6The same install hook makes an outbound POST to a Canarytokens URL.
package.jsonView on unpkg · L6The lifecycle behavior runs on package installation without an explicit user command.
package.jsonView on unpkg · L5Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
test.jsView on unpkgSource matches reverse-shell style process and socket wiring.
package.json#scripts.preinstallView on unpkg · L1This report applies to @nimbusedge/auth@19999.0.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe automatic preinstall hook launches interactive Bash with standard input and output redirected to a remote TCP socket.
package.jsonView on unpkg · L6The same install hook makes an outbound POST to a Canarytokens URL.
package.jsonView on unpkg · L6The lifecycle behavior runs on package installation without an explicit user command.
package.jsonView on unpkg · L5Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
test.jsView on unpkgSource matches reverse-shell style process and socket wiring.
package.json#scripts.preinstallView on unpkg · L1