SECURITY RESEARCH POC - see README
Install lifecycle hooks execute a script that harvests basic host identity data and transmits it to an external webhook. This is an active data-exfiltration behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package automatically runs poc.js during both preinstall and postinstall.
package.jsonView on unpkg · L5The lifecycle script collects the installing host's hostname, account username, and timestamp.
poc.jsView on unpkg · L6It sends that collected data to an external webhook.site URL using an HTTPS GET request.
poc.jsView on unpkg · L13This report applies to bnppf-flag-icons@99.99.99.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package automatically runs poc.js during both preinstall and postinstall.
package.jsonView on unpkg · L5The lifecycle script collects the installing host's hostname, account username, and timestamp.
poc.jsView on unpkg · L6It sends that collected data to an external webhook.site URL using an HTTPS GET request.
poc.jsView on unpkg · L13