Importing the package in a browser fetches an authenticated profile and exfiltrates page data or cookies through a redirect. This is a concrete credential and data theft path.
The primary entry runs immediately and fetches an authenticated profile.
package.jsonView on unpkg · L1The primary entry runs immediately and fetches an authenticated profile.
index.jsView on unpkg · L1It reads page content and browser cookies, then redirects to a webhook URL carrying the collected value.
index.jsView on unpkg · L3This report applies to pf25262@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
The redirect sends either a matched token or a cookie-derived fallback to a third party.
index.jsView on unpkg · L3The primary entry runs immediately and fetches an authenticated profile.
package.jsonView on unpkg · L1The primary entry runs immediately and fetches an authenticated profile.
index.jsView on unpkg · L1It reads page content and browser cookies, then redirects to a webhook URL carrying the collected value.
index.jsView on unpkg · L3The redirect sends either a matched token or a cookie-derived fallback to a third party.
index.jsView on unpkg · L3