An automatic install hook gathers host and user environment details and sends them to an external collection endpoint.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package runs index.js automatically during preinstall.
package.jsonView on unpkg · L8Source collects local host identity data and sends it to an external endpoint.
index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgThe install script collects the user home directory, hostname, username, DNS servers, and package metadata.
index.jsView on unpkg · L8It posts the collected data to a hard-coded Pipedream endpoint.
index.jsView on unpkg · L24The request body is transmitted and ended by the script.
index.jsView on unpkg · L41This report applies to eslint-plugin-skywagon-web@100.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package runs index.js automatically during preinstall.
package.jsonView on unpkg · L8Source collects local host identity data and sends it to an external endpoint.
index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgThe install script collects the user home directory, hostname, username, DNS servers, and package metadata.
index.jsView on unpkg · L8It posts the collected data to a hard-coded Pipedream endpoint.
index.jsView on unpkg · L24The request body is transmitted and ended by the script.
index.jsView on unpkg · L41