Simple PoC package for testing for dependency confusion vulnerabilities.
An install-time hook silently transmits host and environment-identifying information to an external webhook. This is a confirmed data-exfiltration surface.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package identifies itself as git-en-boite-logging version 0.0.0.
package.jsonView on unpkg · L2Its test script sends the current user, working directory, and hostname to a webhook URL.
package.jsonView on unpkg · L7Its automatic preinstall hook performs the same silent transmission during installation.
package.jsonView on unpkg · L8Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgAn npm script contacts a known out-of-band callback or webhook service.
package.json#scripts.testView on unpkgAn npm script sends host identity through command substitution to a fixed external destination.
package.json#scripts.testView on unpkgThis report applies to git-en-boite-logging@0.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe package identifies itself as git-en-boite-logging version 0.0.0.
package.jsonView on unpkg · L2Its test script sends the current user, working directory, and hostname to a webhook URL.
package.jsonView on unpkg · L7Its automatic preinstall hook performs the same silent transmission during installation.
package.jsonView on unpkg · L8Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgAn npm script contacts a known out-of-band callback or webhook service.
package.json#scripts.testView on unpkgAn npm script sends host identity through command substitution to a fixed external destination.
package.json#scripts.testView on unpkg