Security Research PoC
Installation automatically collects host and user information and sends it to a fixed external webhook. The same behavior executes when the entrypoint is imported.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
index.jsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
index.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkg · L1Source collects local host identity data and sends it to an external endpoint.
index.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgThis report applies to hyperion-react-native-testapp@999.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L7Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
index.jsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
index.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkg · L1Source collects local host identity data and sends it to an external endpoint.
index.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkg