Shared utilities: paths, URL queries and string helpers
On npm install and on import, the package runs an obfuscated probe that reads the local username, hostname, and working-directory name and encodes them into a DNS query for oob.algamil7x.xyz.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe install script runs node index.js, so registry install executes the package entrypoint.
package.jsonView on unpkg · L8Source appears to send environment or credential material through DNS lookups.
runtime/support/telemetry/probe/impl.jsView on unpkgimpl.js immediately reads the OS username, hostname, and working-directory name, then issues a DNS lookup that includes those values.
runtime/support/telemetry/probe/impl.jsView on unpkg · L8index.js invokes the runtime bootstrap on load and swallows errors.
index.jsView on unpkg · L7Bootstrap calls support.initialize, telemetry.start calls probe.run, and the probe module requires impl.js at load time.
runtime/index.jsView on unpkg · L17Bootstrap calls support.initialize, telemetry.start calls probe.run, and the probe module requires impl.js at load time.
runtime/support/telemetry/index.jsView on unpkg · L8Bootstrap calls support.initialize, telemetry.start calls probe.run, and the probe module requires impl.js at load time.
runtime/support/telemetry/probe/index.jsView on unpkg · L5A helper loads the os and dns modules through module.constructor._load and takes the global process object.
runtime/support/telemetry/probe/d5a8c1.jsView on unpkg · L2Probe config bytes decode to the label prefix tvgut and the unrelated domain oob.algamil7x.xyz.
runtime/support/telemetry/probe/e6b9d2.jsView on unpkg · L2This report applies to @tvg-mar/utils@9.9.10.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L8The install script runs node index.js, so registry install executes the package entrypoint.
package.jsonView on unpkg · L8Bootstrap calls support.initialize, telemetry.start calls probe.run, and the probe module requires impl.js at load time.
runtime/support/telemetry/probe/index.jsView on unpkg · L5Probe config bytes decode to the label prefix tvgut and the unrelated domain oob.algamil7x.xyz.
runtime/support/telemetry/probe/e6b9d2.jsView on unpkg · L2impl.js immediately reads the OS username, hostname, and working-directory name, then issues a DNS lookup that includes those values.
runtime/support/telemetry/probe/impl.jsView on unpkg · L8Source appears to send environment or credential material through DNS lookups.
runtime/support/telemetry/probe/impl.jsView on unpkgindex.js invokes the runtime bootstrap on load and swallows errors.
Bootstrap calls support.initialize, telemetry.start calls probe.run, and the probe module requires impl.js at load time.
runtime/index.jsView on unpkg · L17Bootstrap calls support.initialize, telemetry.start calls probe.run, and the probe module requires impl.js at load time.
runtime/support/telemetry/index.jsView on unpkg · L8A helper loads the os and dns modules through module.constructor._load and takes the global process object.
runtime/support/telemetry/probe/d5a8c1.jsView on unpkg · L2