Importing the package immediately reads browser cookies, probes local app routes for flag-shaped secrets, and POSTs the bundle to a package-controlled webhook.site URL. There is no user flag or destination allowlist.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
index.jsView on unpkgA manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgMain index.js is an immediately invoked async function that POSTs harvested data to a hardcoded webhook.site URL with no opt-in.
index.jsView on unpkg · L1This report applies to pf25133@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Main index.js is an immediately invoked async function that POSTs harvested data to a hardcoded webhook.site URL with no opt-in.
index.jsView on unpkg · L8The payload includes document.cookie plus HTTP status and any DGA flag matches from probed application routes.
index.jsView on unpkg · L4package.json sets index.js as main, so importing or requiring the package runs the theft by default.
package.jsonView on unpkg · L1Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
index.jsView on unpkgA manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgMain index.js is an immediately invoked async function that POSTs harvested data to a hardcoded webhook.site URL with no opt-in.
index.jsView on unpkg · L1Main index.js is an immediately invoked async function that POSTs harvested data to a hardcoded webhook.site URL with no opt-in.
index.jsView on unpkg · L8The payload includes document.cookie plus HTTP status and any DGA flag matches from probed application routes.
index.jsView on unpkg · L4package.json sets index.js as main, so importing or requiring the package runs the theft by default.
package.jsonView on unpkg · L1