Loading script.js in a browser assigns window.location.href to a webhook.site URL plus document.cookie. The cookie string is sent to that host as part of the navigation request.
main and unpkg both point at script.js, so the file runs when the package script is loaded in a page.
package.jsonView on unpkg · L5String pieces are joined into location.href and document.cookie, then the browser is sent to a webhook.site URL with the cookie string appended.
script.jsView on unpkg · L1String pieces are joined into location.href and document.cookie, then the browser is sent to a webhook.site URL with the cookie string appended.
script.jsView on unpkg · L6This report applies to npmscript_tesstalert_unpkg@1.1.8.
See version security history for other recorded verdicts.
Evidence last updated: .
main and unpkg both point at script.js, so the file runs when the package script is loaded in a page.
package.jsonView on unpkg · L5String pieces are joined into location.href and document.cookie, then the browser is sent to a webhook.site URL with the cookie string appended.
script.jsView on unpkg · L1String pieces are joined into location.href and document.cookie, then the browser is sent to a webhook.site URL with the cookie string appended.
script.jsView on unpkg · L6