SECURITY PLACEHOLDER: Reserved by Tellyo to prevent dependency-confusion / npm-squatting attacks. Stylesheet-only, no code, no install scripts. Do not install.
An automatic install hook transmits host uptime information to an external endpoint. Shell-variable assembly obscures the curl command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json automatically runs test.sh through preinstall.
package.jsonView on unpkg · L11Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgtest.sh constructs curl from shell variables and posts uptime output to https://abbishal.com/sh/poc without an opt-in gate.
test.shView on unpkg · L13test.sh claims to collect nothing and be invisible to malware scanners, contradicting its active transmission and attempting to excuse the behavior.
test.shView on unpkg · L10A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
colours.scssView on unpkgThis report applies to abbishal-poc2@1.2.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L12Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L12package.json automatically runs test.sh through preinstall.
package.jsonView on unpkg · L11A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
colours.scssView on unpkgtest.sh claims to collect nothing and be invisible to malware scanners, contradicting its active transmission and attempting to excuse the behavior.
test.shView on unpkg · L10test.sh constructs curl from shell variables and posts uptime output to https://abbishal.com/sh/poc without an opt-in gate.
test.shView on unpkg · L13