Security research canary package (dependency confusion detection). Published as part of an authorized bug bounty program. See README.md.
Installation automatically collects data from the host and installing project, then sends it to external collectors. This is a concrete install-time data-exfiltration surface.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
payload.jsView on unpkg · L4A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
payload.jsView on unpkg · L4Source collects local host identity data and sends it to an external endpoint.
payload.jsView on unpkg · L4Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
payload.jsView on unpkg · L4This report applies to @pwaplatform/module-sso-integration@99.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
payload.jsView on unpkg · L4A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
payload.jsView on unpkg · L4Source collects local host identity data and sends it to an external endpoint.
payload.jsView on unpkg · L4Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
payload.jsView on unpkg · L4