Web
When a user opens the HTML page and clicks Publish, it transmits their npm bearer token and selected package payload through a third-party Worker. This creates a credential and package-data exfiltration path.
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe HTML embeds a prefilled npm authentication token in the password input.
index.htmlView on unpkg · L80The same request includes all selected package-file contents, allowing the proxy to receive private package data.
app.jsView on unpkg · L141This report applies to @vbansal67/official-publisher@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.htmlView on unpkgThe HTML embeds a prefilled npm authentication token in the password input.
index.htmlView on unpkg · L80The same request includes all selected package-file contents, allowing the proxy to receive private package data.
app.jsView on unpkg · L141