Importing the module in a browser starts a two-second timer that reads an auth token or the full localStorage dump and POSTs it to /addPost. There is no other product behavior.
index.js runs a top-level setTimeout on import, not behind an exported API.
index.jsView on unpkg · L1It reads localStorage key token or stringifies the entire localStorage object.
index.jsView on unpkg · L2Stolen data is POSTed with fetch to /addPost as JSON content.
index.jsView on unpkg · L3The package name analytics-widget has no analytics behavior; main is this harvester.
package.jsonView on unpkg · L2This report applies to analytics-widget@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
index.js runs a top-level setTimeout on import, not behind an exported API.
index.jsView on unpkg · L1It reads localStorage key token or stringifies the entire localStorage object.
index.jsView on unpkg · L2Stolen data is POSTed with fetch to /addPost as JSON content.
index.jsView on unpkg · L3The package name analytics-widget has no analytics behavior; main is this harvester.
package.jsonView on unpkg · L2