Installation automatically executes code that fingerprints the host and transmits the result to an unrelated fixed webhook. This is unconsented host-data exfiltration.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe postinstall hook automatically runs main.js during installation.
package.jsonView on unpkg · L9Source collects local host identity data and sends it to an external endpoint.
main.jsView on unpkg · L2A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
main.jsView on unpkgmain.js collects hostname, username, platform, working directory, Node version, and lifecycle environment data.
main.jsView on unpkg · L8The collected host data is POSTed to a fixed webhook.site callback.
main.jsView on unpkg · L21This report applies to sql-limit-enforcer@10.0.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe postinstall hook automatically runs main.js during installation.
package.jsonView on unpkg · L9Source collects local host identity data and sends it to an external endpoint.
main.jsView on unpkg · L2A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
main.jsView on unpkgmain.js collects hostname, username, platform, working directory, Node version, and lifecycle environment data.
main.jsView on unpkg · L8The collected host data is POSTed to a fixed webhook.site callback.
main.jsView on unpkg · L21