The exposed browser script posts page cookies to a third-party webhook. This is a concrete credential exfiltration surface.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
script.jsView on unpkgA manifest entrypoint or package-local install chain reaches a fixed external POST callback.
script.jsView on unpkgscript.js sends the browser's document.cookie in a POST request to a third-party webhook URL.
script.jsView on unpkg · L2The package exposes script.js as both its main and unpkg entrypoint.
package.jsonView on unpkg · L5This report applies to npmscript_tesstalert_unpkg@1.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
script.js sends the browser's document.cookie in a POST request to a third-party webhook URL.
script.jsView on unpkg · L2Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
script.jsView on unpkgA manifest entrypoint or package-local install chain reaches a fixed external POST callback.
script.jsView on unpkgThe package exposes script.js as both its main and unpkg entrypoint.
package.jsonView on unpkg · L5