BUGBOUNTY PoC — represents @subsplash/intercom — @subsplash/intercom (2 refs) — Subsplash report 7a8faa0b
The package runs an unconsented preinstall hook. It gathers host-identifying information and transmits it to a local HTTP listener while hiding failures.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgThe manifest identifies this package as a public-package impersonation proof of concept.
package.jsonView on unpkg · L2An automatic preinstall hook collects the local hostname and account name, sends them to a local HTTP receiver, and suppresses errors.
package.jsonView on unpkg · L7A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.json#scripts.preinstallView on unpkgThe runtime entrypoint explicitly announces public-package dependency confusion.
index.jsView on unpkg · L1This report applies to @rutxploit-sec/subsplash-intercom@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgThe manifest identifies this package as a public-package impersonation proof of concept.
package.jsonView on unpkg · L2An automatic preinstall hook collects the local hostname and account name, sends them to a local HTTP receiver, and suppresses errors.
package.jsonView on unpkg · L7A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.json#scripts.preinstallView on unpkgThe runtime entrypoint explicitly announces public-package dependency confusion.
index.jsView on unpkg · L1