embedding data from esoftplay framework (web based) into mobile app
Explicit configuration-backup commands upload a project configuration file and host metadata to a hard-coded Telegram recipient. The install hook also modifies the consumer package metadata.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/packager.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
bin/cli.jsView on unpkg · L2Source appears to send environment or credential material to an external endpoint.
bin/cli.jsView on unpkg · L2This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/build.jsView on unpkgPackage source invokes a package manager install command at runtime.
bin/build.jsView on unpkg · L401Source file is highly similar to a previously finalized malicious package; route for source-aware review.
modules/lib/utils.tsView on unpkgThis report applies to esoftplay@0.0.269-beta8d1f009.
See version security history for other recorded verdicts.
Evidence last updated: .
Source passes code obtained from a remote response into a dynamic execution sink.
bin/cli.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
bin/cli.jsView on unpkg · L2A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
bin/cli.jsView on unpkg · L2A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cli.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/build.jsView on unpkgPackage source invokes a package manager install command at runtime.
bin/build.jsView on unpkg · L401Source file is highly similar to a previously finalized malicious package; route for source-aware review.
modules/lib/utils.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/packager.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
bin/cli.jsView on unpkg · L2Source appears to send environment or credential material to an external endpoint.
bin/cli.jsView on unpkg · L2Source passes code obtained from a remote response into a dynamic execution sink.
bin/cli.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
bin/cli.jsView on unpkg · L2A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
bin/cli.jsView on unpkg · L2A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cli.jsView on unpkg