Installation automatically collects host metadata and requests the public IP service. The release also carries fixed-webhook and DNS exfiltration routines, but its invalid callback URL aborts the sequence before they run.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
callback.jsView on unpkg · L11Source appears to send environment or credential material to an external endpoint.
callback.jsView on unpkg · L11Source appears to send environment or credential material through DNS lookups.
callback.jsView on unpkg · L11A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
callback.jsView on unpkg · L11Manifest-reachable source sends caller or host-sensitive data to a package-embedded authenticated webhook.
callback.jsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
callback.jsView on unpkg · L11Source fingerprint signature matches a known malicious package signature; route for source-aware review.
callback.jsView on unpkgThis report applies to idx_form_script@999.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
callback.jsView on unpkg · L11Source appears to send environment or credential material to an external endpoint.
callback.jsView on unpkg · L11Source appears to send environment or credential material through DNS lookups.
callback.jsView on unpkg · L11A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
callback.jsView on unpkg · L11Manifest-reachable source sends caller or host-sensitive data to a package-embedded authenticated webhook.
callback.jsView on unpkgA manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
callback.jsView on unpkg · L11Source fingerprint signature matches a known malicious package signature; route for source-aware review.
callback.jsView on unpkg