Loading npm security reports…
The package's published browser entrypoint exfiltrates the current page's cookies to a webhook.site endpoint. No install hook is involved.
Package metadata exposes script.js as both the CommonJS main entrypoint and unpkg asset.
package.jsonView on unpkg · L5The entry script reads document.cookie and assigns a webhook.site URL containing it to an Image source, sending browser cookies to a third party.
script.jsView on unpkg · L2This report applies to npmscript_tesstalert_unpkg@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package metadata exposes script.js as both the CommonJS main entrypoint and unpkg asset.
package.jsonView on unpkg · L5The entry script reads document.cookie and assigns a webhook.site URL containing it to an Image source, sending browser cookies to a third party.
script.jsView on unpkg · L2