An awesome developer dashboard.
A hidden runtime payload steals browser credentials, application sessions, and host data, then exfiltrates them. It also captures screenshots and archives session directories.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
index.jsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
index.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
index.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
index.jsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
index.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
index.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkg