Loading npm security reports…
The package exfiltrates profile response content to a third-party webhook when its main module is imported.
Importing the main module requests profile data, extracts a flag-like value or the first 300 characters, and sends it to an external webhook.
index.jsView on unpkg · L1The manifest makes index.js the package entry point, so this behavior runs when the package is imported.
package.jsonView on unpkg · L1This report applies to pflag29424@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Importing the main module requests profile data, extracts a flag-like value or the first 300 characters, and sends it to an external webhook.
index.jsView on unpkg · L1The manifest makes index.js the package entry point, so this behavior runs when the package is imported.
package.jsonView on unpkg · L1