Polyfill for HTML popover anchor positioning
The published registry source contains immediate system reconnaissance and external data transmission. The bundled registry manifest points loaders to that source.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
thunderboltRegistry.jsView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
thunderboltRegistry.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
thunderboltRegistry.jsView on unpkgLoading thunderboltRegistry.js immediately collects the hostname and sends data to a fixed external HTTP endpoint.
thunderboltRegistry.jsView on unpkg · L11The registry source executes an identity command and forwards its output.
thunderboltRegistry.jsView on unpkg · L25The registry source reads /etc/hosts through a shell command and forwards its contents.
thunderboltRegistry.jsView on unpkg · L45The manifest publishes the registry source alongside the default entrypoint.
package.jsonView on unpkg · L5The registry manifest directs registry loaders to the executable registry source.
registry-manifest.min.jsonView on unpkg · L2This report applies to popover-anchor-polyfill@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Loading thunderboltRegistry.js immediately collects the hostname and sends data to a fixed external HTTP endpoint.
thunderboltRegistry.jsView on unpkg · L11Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
thunderboltRegistry.jsView on unpkg · L10The registry source executes an identity command and forwards its output.
thunderboltRegistry.jsView on unpkg · L25The registry source reads /etc/hosts through a shell command and forwards its contents.
thunderboltRegistry.jsView on unpkg · L45Source file is highly similar to a previously finalized malicious package; route for source-aware review.
thunderboltRegistry.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
thunderboltRegistry.jsView on unpkgThe registry manifest directs registry loaders to the executable registry source.
registry-manifest.min.jsonView on unpkg · L2The manifest publishes the registry source alongside the default entrypoint.
package.jsonView on unpkg · L5