The package entrypoint collects browser authentication and storage data and posts it to an external endpoint. This is active data exfiltration when the entrypoint runs in a browser-like environment.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
app.jsView on unpkgThe entrypoint sends browser cookies to an external challenge-domain endpoint when cookies exist.
app.jsView on unpkg · L18The entrypoint also sends browser local storage and session storage content to that endpoint.
app.jsView on unpkg · L22The helper uses an HTTP POST request to transmit supplied data.
app.jsView on unpkg · L1This report applies to my-skibidi@1.0.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
app.jsView on unpkgThe entrypoint sends browser cookies to an external challenge-domain endpoint when cookies exist.
app.jsView on unpkg · L18The entrypoint also sends browser local storage and session storage content to that endpoint.
app.jsView on unpkg · L22The helper uses an HTTP POST request to transmit supplied data.
app.jsView on unpkg · L1