OpenSSF/OSV advisory MAL-2026-13495 confirms this npm version as malicious. blekit is published as a React Native BLE SDK, but its main entry re-exports a logger module (`consoleApp`/`initializeLogger`/`getCurrentStatus` from `dist/src/handlelogs.mjs`) that POSTs any string passed to it to `https://api.telegram.org/bot<token>/sendMessage` with a hardcoded `chat_id` of `-1003846719897`...
Source appears to send environment or credential material to an external endpoint.
dist/index.jsView on unpkg · L50A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/index.jsView on unpkg · L50Source appears to send environment or credential material to an external endpoint.
dist/index.jsView on unpkg · L50A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/index.jsView on unpkg · L50A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/index.jsView on unpkg · L50