The package's main module steals browser session-related data and authenticated profile content. It sends the collected data to a third-party webhook.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
index.jsView on unpkgA manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgThis report applies to pf23727@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
The main entry point immediately collects browser cookies and page HTML, then sends them to a fixed webhook.
It also fetches the authenticated local /profile endpoint and exfiltrates its response to the same webhook.
index.jsView on unpkg · L5Importing the configured main file triggers this code without an exported or user-invoked function.
package.jsonView on unpkg · L1Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
index.jsView on unpkgA manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgThe main entry point immediately collects browser cookies and page HTML, then sends them to a fixed webhook.
index.jsView on unpkg · L1It also fetches the authenticated local /profile endpoint and exfiltrates its response to the same webhook.
index.jsView on unpkg · L5Importing the configured main file triggers this code without an exported or user-invoked function.
package.jsonView on unpkg · L1