AUTHORISED SECURITY RESEARCH — dependency confusion proof of concept. This package was published because the name appeared in publicly served code but was unregistered on the public registry. If it is in your dependency tree, your resolver fetched an inte
npm preinstall executes a telemetry beacon without user action. It reads host and consuming-project metadata, then sends it through DNS and HTTP(S) to a fixed external callback.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgCollects host, username, home path, local/public IPs, working directory, and consuming-project metadata.
index.jsView on unpkg · L35Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L11Collects host, username, home path, local/public IPs, working directory, and consuming-project metadata.
index.jsView on unpkg · L35A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkg