Lightweight, license-gated React component for embedding a Twitter/X timeline
Mounting the exported React component performs hidden licence validation. If validation fails outside a body hostname, it replaces the page body.
Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.js#virtual:normalized:round1View on unpkgThe ESM entrypoint is deliberately obfuscated, concealing its runtime behavior.
index.mjsView on unpkg · L1On component use, it fetches and decodes a remote revocation list.
index.mjsView on unpkg · L1On component use, it fetches and decodes a remote revocation list.
index.mjsView on unpkg · L1The package claims MIT licensing but includes an undocumented remote licence-revocation system.
package.jsonView on unpkg · L4This report applies to rc-twitter-embed@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
An invalid licence can replace the consumer page body with a newly created element.
index.mjsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
index.js#virtual:normalized:round1View on unpkgThe ESM entrypoint is deliberately obfuscated, concealing its runtime behavior.
index.mjsView on unpkg · L1On component use, it fetches and decodes a remote revocation list.
index.mjsView on unpkg · L1On component use, it fetches and decodes a remote revocation list.
index.mjsView on unpkg · L1An invalid licence can replace the consumer page body with a newly created element.
index.mjsView on unpkg · L1The package claims MIT licensing but includes an undocumented remote licence-revocation system.
package.jsonView on unpkg · L4