Installation triggers a shell command that lists cron-named files under `/tmp` and writes the result to another temporary file. No confirmed exfiltration, execution, or persistence follows.
Package defines install-time lifecycle scripts.
package.jsonView on unpkg`postinstall` executes automatically during npm installation.
package.jsonView on unpkg · L6It enumerates `/tmp/cron*` and appends the listing to `/tmp/test.txt`.
package.jsonView on unpkg · L7Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThis report applies to randompkga@1.0.18.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg`postinstall` executes automatically during npm installation.
package.jsonView on unpkg · L6It enumerates `/tmp/cron*` and appends the listing to `/tmp/test.txt`.
package.jsonView on unpkg · L7Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg