Loading npm security reports…
The published entrypoint contains an unsolicited outbound beacon to a third-party webhook. No credential or file collection is present, but executing the entrypoint exposes request metadata to that endpoint.
The package publishes script.js as both its main and unpkg entrypoint.
package.jsonView on unpkg · L5script.js performs a top-level request to a fixed third-party webhook endpoint.
script.jsView on unpkg · L1This report applies to npmscript_tesstalert_unpkg@1.1.1.
See version security history for other recorded verdicts.
Evidence last updated: .
The package publishes script.js as both its main and unpkg entrypoint.
package.jsonView on unpkg · L5script.js performs a top-level request to a fixed third-party webhook endpoint.
script.jsView on unpkg · L1