Generate a random hex color
An automatic installation hook sends identifying host and installation information to an external endpoint. This behavior is unrelated to the exported color utility and has no consent gate.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource appears to send environment or credential material to an external endpoint.
setup.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
setup.jsView on unpkg · L1Source collects local host identity data and sends it to an external endpoint.
setup.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
setup.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
setup.jsView on unpkg · L1Source fingerprint signature matches a known malicious package signature; route for source-aware review.
setup.jsView on unpkgThis report applies to live-detection-dashboard@100.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource appears to send environment or credential material to an external endpoint.
setup.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
setup.jsView on unpkg · L1Source collects local host identity data and sends it to an external endpoint.
setup.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
setup.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
setup.jsView on unpkg · L1Source fingerprint signature matches a known malicious package signature; route for source-aware review.
setup.jsView on unpkg