Benign canary package #2 for authorized security testing of an MCP scanner. No harmful behavior.
The package transmits the installing or importing machine's hostname to a third-party webhook. It runs automatically at postinstall and when its main module is imported.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe postinstall lifecycle hook automatically runs beacon.js.
package.jsonView on unpkg · L6Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgbeacon.js sends the machine hostname and execution stage to a third-party webhook.
beacon.jsView on unpkg · L1This report applies to @yongot/canary-mcp-test-2@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe postinstall lifecycle hook automatically runs beacon.js.
package.jsonView on unpkg · L6Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgbeacon.js sends the machine hostname and execution stage to a third-party webhook.
beacon.jsView on unpkg · L1