Importing the package immediately fetches a remote /profile URL and relays the body, or the error and stack, to webhook.site. There is no documented library behavior; the only runtime work is this outbound chain.
package.json sets main to index.js and has empty description, author, and keywords, with no library API.
package.jsonView on unpkg · L2index.js runs fetch at top level with no exports, so requiring the package immediately starts a network chain.
index.jsView on unpkg · L1The /profile response body is URL-encoded and sent to webhook.site.
index.jsView on unpkg · L3Fetch failures send the error message and stack trace to the same webhook.site URL.
index.jsView on unpkg · L4This report applies to ragacateslikodi@1.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
package.json sets main to index.js and has empty description, author, and keywords, with no library API.
package.jsonView on unpkg · L2index.js runs fetch at top level with no exports, so requiring the package immediately starts a network chain.
index.jsView on unpkg · L1The /profile response body is URL-encoded and sent to webhook.site.
index.jsView on unpkg · L3Fetch failures send the error message and stack trace to the same webhook.site URL.
index.jsView on unpkg · L4