Minimal npx package that POSTs package name and whoami to an OOB callback
Running the exposed CLI sends the current account name, hostname, platform, and package name to an external callback. This is unconsented host-identity exfiltration.
Source collects local host identity data and sends it to an external endpoint.
bin/cli.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/cli.jsView on unpkgThe command collects the local account name and host identity and posts them to an unrelated external callback.
bin/cli.jsView on unpkg · L7The command collects the local account name and host identity and posts them to an unrelated external callback.
bin/cli.jsView on unpkg · L24The command collects the local account name and host identity and posts them to an unrelated external callback.
bin/cli.jsView on unpkg · L35A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThe manifest describes the package as sending the package name and current user to an out-of-band callback.
package.jsonView on unpkg · L4The command collects the local account name and host identity and posts them to an unrelated external callback.
bin/cli.jsView on unpkg · L7The command collects the local account name and host identity and posts them to an unrelated external callback.
bin/cli.jsView on unpkg · L24Source collects local host identity data and sends it to an external endpoint.
bin/cli.jsView on unpkg · L2The command collects the local account name and host identity and posts them to an unrelated external callback.
bin/cli.jsView on unpkg · L35Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/cli.jsView on unpkgThe manifest describes the package as sending the package name and current user to an out-of-band callback.
package.jsonView on unpkg · L4A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkg