Loading the module in a page automatically fetches the same-origin profile, copies a flag or the page HTML, and posts it to the feed. This is unattended harvest and publish, not a callable helper.
index.js runs a 2-second timer at load with no exports or user-facing API.
index.jsView on unpkg · L1On that timer it fetches /profile and scrapes .flag-value, or the full profile HTML if that node is missing.
index.jsView on unpkg · L5It POSTs the stolen text to /addPost as JSON, which publishes the secret on the same origin.
index.jsView on unpkg · L8package.json has an empty description and no other entrypoints; main points at this payload.
package.jsonView on unpkg · L1This report applies to feed-widget-helper@1.0.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
index.js runs a 2-second timer at load with no exports or user-facing API.
index.jsView on unpkg · L1On that timer it fetches /profile and scrapes .flag-value, or the full profile HTML if that node is missing.
index.jsView on unpkg · L5It POSTs the stolen text to /addPost as JSON, which publishes the secret on the same origin.
index.jsView on unpkg · L8package.json has an empty description and no other entrypoints; main points at this payload.
package.jsonView on unpkg · L1