Installing the package automatically transmits host-identifying data to an external server twice. The requests are silent and unrelated to any implemented package function.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe preinstall hook sends the current user, hostname, working directory, and timestamp to a remote HTTP endpoint.
package.jsonView on unpkg · L5The postinstall hook repeats the same undisclosed host-fingerprinting request after installation.
package.jsonView on unpkg · L6Both hooks suppress failures, hiding the network action from normal installation output.
package.jsonView on unpkg · L5Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgAn npm script sends host identity through command substitution to a fixed external destination.
package.json#scripts.preinstallView on unpkgThis report applies to @traktis/core@99.99.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe preinstall hook sends the current user, hostname, working directory, and timestamp to a remote HTTP endpoint.
package.jsonView on unpkg · L5The postinstall hook repeats the same undisclosed host-fingerprinting request after installation.
package.jsonView on unpkg · L6Both hooks suppress failures, hiding the network action from normal installation output.
package.jsonView on unpkg · L5Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgAn npm script sends host identity through command substitution to a fixed external destination.
package.json#scripts.preinstallView on unpkg