embedding data from esoftplay framework (web based) into mobile app
No attack surface was identified. The automatic hook performs framework setup, but inspected source did not show credential sending, remote payload loading, or AI-agent control changes.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. A high or critical static finding has no usable source path. These conditions do not mean that the AI confirmed malicious behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/packager.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
bin/cli.jsView on unpkg · L2Source appears to send environment or credential material to an external endpoint.
bin/cli.jsView on unpkg · L2Package source invokes a package manager install command at runtime.
bin/build.jsView on unpkg · L401Source file is highly similar to a previously finalized malicious package; route for source-aware review.
modules/lib/utils.tsView on unpkgThis report applies to esoftplay@0.0.269-beta934b397.
See version security history for other recorded verdicts.
Evidence last updated: .
Source passes code obtained from a remote response into a dynamic execution sink.
bin/cli.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
bin/cli.jsView on unpkg · L2A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
bin/cli.jsView on unpkg · L2A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cli.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L11Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L11Package source invokes a package manager install command at runtime.
bin/build.jsView on unpkg · L401Source file is highly similar to a previously finalized malicious package; route for source-aware review.
modules/lib/utils.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/packager.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
bin/cli.jsView on unpkg · L2Source appears to send environment or credential material to an external endpoint.
bin/cli.jsView on unpkg · L2Source passes code obtained from a remote response into a dynamic execution sink.
bin/cli.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
bin/cli.jsView on unpkg · L2A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
bin/cli.jsView on unpkg · L2A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cli.jsView on unpkg