Importing the package immediately fetches /profile and forwards the body, or the error text, to an attacker-controlled webhook.site URL. There is no legitimate library surface; the main module is only this leak.
index.js runs at import time: it fetches /profile and sends the response body to webhook.site.
index.jsView on unpkg · L1The same webhook.site URL also receives encoded error strings if the first request fails.
index.jsView on unpkg · L4package.json sets main to index.js, so requiring the package executes that exfil chain with no exported API.
package.jsonView on unpkg · L2This report applies to ragacateslikodi@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
index.js runs at import time: it fetches /profile and sends the response body to webhook.site.
index.jsView on unpkg · L1The same webhook.site URL also receives encoded error strings if the first request fails.
index.jsView on unpkg · L4package.json sets main to index.js, so requiring the package executes that exfil chain with no exported API.
package.jsonView on unpkg · L2