Loading npm security reports…
The runtime entrypoint transfers the content of a profile endpoint to a fixed external webhook. This is confirmed data exfiltration on import.
A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgImporting the entrypoint requests /profile and posts its response to a fixed third-party webhook.
index.jsView on unpkg · L1This report applies to pulse-pwn-9f3a2@1.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgImporting the entrypoint requests /profile and posts its response to a fixed third-party webhook.
index.jsView on unpkg · L1