Exposes Apple's StoreKit.framework to Unity developers via C# script API
The package entrypoint is a load-time callback that sends host identity to an external oast.fun collector. It does not implement the claimed StoreKit API.
The only runtime entry is index.js, declared as main, and it performs no StoreKit or Unity work.
package.jsonView on unpkg · L1On load, index.js builds an https URL on an unrelated oast.fun host that includes the machine platform and hostname, then calls https.get and discards the response.
index.jsView on unpkg · L6On load, index.js builds an https URL on an unrelated oast.fun host that includes the machine platform and hostname, then calls https.get and discards the response.
index.jsView on unpkg · L9This report applies to com.apple.unityplugin.storekit@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
The only runtime entry is index.js, declared as main, and it performs no StoreKit or Unity work.
package.jsonView on unpkg · L1On load, index.js builds an https URL on an unrelated oast.fun host that includes the machine platform and hostname, then calls https.get and discards the response.
index.jsView on unpkg · L6On load, index.js builds an https URL on an unrelated oast.fun host that includes the machine platform and hostname, then calls https.get and discards the response.
index.jsView on unpkg · L9