embedding data from esoftplay framework (web based) into mobile app
The package contains hard-coded Telegram reporting that uploads project configuration and sends workstation and build metadata. It also mutates the consuming project and dependency files during postinstall.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/packager.jsView on unpkgPackage source references dynamic require/import behavior.
bin/packager.jsView on unpkg · L1Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
bin/cli.jsView on unpkg · L2Source appears to send environment or credential material to an external endpoint.
bin/cli.jsView on unpkg · L2Package source invokes a package manager install command at runtime.
bin/build.jsView on unpkg · L400Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/build.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
modules/lib/utils.tsView on unpkgSource passes code obtained from a remote response into a dynamic execution sink.
bin/cli.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
bin/cli.jsView on unpkg · L2A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
bin/cli.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cli.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L11Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L11Package source invokes a package manager install command at runtime.
bin/build.jsView on unpkg · L400Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/build.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
modules/lib/utils.tsView on unpkgPackage source references dynamic require/import behavior.
bin/packager.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/packager.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
bin/cli.jsView on unpkg · L2Source appears to send environment or credential material to an external endpoint.
bin/cli.jsView on unpkg · L2Source passes code obtained from a remote response into a dynamic execution sink.
bin/cli.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
bin/cli.jsView on unpkg · L2A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
bin/cli.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cli.jsView on unpkg