Compatibility shim.
Installation automatically reports local machine and project path details to an external endpoint. This is an active data exfiltration surface.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package runs beacon.cjs automatically during installation through a postinstall hook.
package.jsonView on unpkg · L7Source collects local host identity data and sends it to an external endpoint.
beacon.cjsView on unpkg · L3Source fingerprint signature matches a known malicious package signature; route for source-aware review.
beacon.cjsView on unpkgThe transmitted payload includes the machine hostname, install path, working directory, and npm runtime version.
beacon.cjsView on unpkg · L26Importing the package entrypoint calls `fire()` from `beacon.cjs`.
index.jsView on unpkg · L4This report applies to browser-metrics-plugin.contrib@99.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L7The package runs beacon.cjs automatically during installation through a postinstall hook.
package.jsonView on unpkg · L7Source collects local host identity data and sends it to an external endpoint.
beacon.cjsView on unpkg · L3The transmitted payload includes the machine hostname, install path, working directory, and npm runtime version.
beacon.cjsView on unpkg · L26Source fingerprint signature matches a known malicious package signature; route for source-aware review.
beacon.cjsView on unpkgImporting the package entrypoint calls `fire()` from `beacon.cjs`.