The package entrypoint harvests browser cookies and data from local application routes, then posts the results to an external webhook. It runs on import.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
index.jsView on unpkgA manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgThe main entrypoint immediately reads browser cookies and sends collected data to a fixed webhook.
index.jsView on unpkg · L4The main entrypoint immediately reads browser cookies and sends collected data to a fixed webhook.
index.jsView on unpkg · L8It probes ten same-origin routes and extracts values matching a flag pattern from responses.
index.jsView on unpkg · L2Importing the declared main file activates the asynchronous collection routine without a user-facing API.
package.jsonView on unpkg · L1This report applies to pflag14570@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
index.jsView on unpkgA manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgThe main entrypoint immediately reads browser cookies and sends collected data to a fixed webhook.
index.jsView on unpkg · L4The main entrypoint immediately reads browser cookies and sends collected data to a fixed webhook.
index.jsView on unpkg · L8It probes ten same-origin routes and extracts values matching a flag pattern from responses.
index.jsView on unpkg · L2Importing the declared main file activates the asynchronous collection routine without a user-facing API.
package.jsonView on unpkg · L1