AUTHORISED SECURITY RESEARCH — dependency confusion proof of concept. This package was published because the name appeared in publicly served code but was unregistered on the public registry. If it is in your dependency tree, your resolver fetched an inte
A preinstall hook fingerprints the installation host and consuming project, then sends the data to an external callback through DNS and HTTP(S). The behavior occurs without an explicit user command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgReads the consuming project's `package.json` via `INIT_CWD`.
index.jsView on unpkg · L36Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L11Reads the consuming project's `package.json` via `INIT_CWD`.
index.jsView on unpkg · L36A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkg