Loading the published entrypoint in a browser copies all localStorage and POSTs it to /addPost. Session tokens and other client secrets stored there leave the page without any user-facing API.
On import, index.js waits two seconds, copies every localStorage key, and POSTs the dump to /addPost.
index.jsView on unpkg · L1package.json has empty description, author, and keywords, no dependencies, and no other source files.
package.jsonView on unpkg · L1This report applies to feed-widget-helper@1.0.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
On import, index.js waits two seconds, copies every localStorage key, and POSTs the dump to /addPost.
index.jsView on unpkg · L1package.json has empty description, author, and keywords, no dependencies, and no other source files.
package.jsonView on unpkg · L1