Importing the module fetches /profile on the current origin and sends the response body, or the error and stack, to webhook.site. There is no other package behavior.
Requiring the published main module immediately fetches /profile and appends the response body to a webhook.site URL.
index.jsView on unpkg · L1The same webhook also receives the error message and stack if the profile request fails.
index.jsView on unpkg · L4The package has empty metadata and no other product code; the only runtime file is this exfiltration chain.
package.jsonView on unpkg · L2This report applies to ragacateslikodi@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Requiring the published main module immediately fetches /profile and appends the response body to a webhook.site URL.
index.jsView on unpkg · L1The same webhook also receives the error message and stack if the profile request fails.
index.jsView on unpkg · L4The package has empty metadata and no other product code; the only runtime file is this exfiltration chain.
package.jsonView on unpkg · L2