Exposes Apple's StoreKit.framework to Unity developers via C# script API
Requiring this package immediately contacts a third-party oast.fun callback and sends the local hostname and operating-system platform in the query string.
Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgindex.js runs on require and builds an HTTPS request to a random oast.fun host that includes the operating-system platform and the machine hostname.
index.jsView on unpkg · L7The request is sent immediately with https.get and the response body is discarded.
index.jsView on unpkg · L10index.js runs on require and builds an HTTPS request to a random oast.fun host that includes the operating-system platform and the machine hostname.
index.jsView on unpkg · L1package.json sets main to index.js and defines only a failing test script, so loading the package is enough to send the beacon.
package.jsonView on unpkg · L11This report applies to com.apple.unityplugin.storekit@1.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
index.js runs on require and builds an HTTPS request to a random oast.fun host that includes the operating-system platform and the machine hostname.
index.jsView on unpkg · L1index.js runs on require and builds an HTTPS request to a random oast.fun host that includes the operating-system platform and the machine hostname.
index.jsView on unpkg · L7The request is sent immediately with https.get and the response body is discarded.
index.jsView on unpkg · L10Source fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgpackage.json sets main to index.js and defines only a failing test script, so loading the package is enough to send the beacon.
package.jsonView on unpkg · L11