Loading npm security reports…
Loading the package entrypoint in a browser causes an unsolicited request to a third-party webhook. No other attack behavior was identified in the inspected source.
The manifest makes script.js the package entrypoint.
package.jsonView on unpkg · L5The entrypoint immediately creates an image whose source is a third-party webhook URL marked as an XSS beacon.
script.jsView on unpkg · L1This report applies to npmscript_tesstalert_unpkg@1.1.3.
See version security history for other recorded verdicts.
Evidence last updated: .
The manifest makes script.js the package entrypoint.
package.jsonView on unpkg · L5The entrypoint immediately creates an image whose source is a third-party webhook URL marked as an XSS beacon.
script.jsView on unpkg · L1