SECURITY RESEARCH - Dependency Confusion PoC
An npm preinstall hook executes a host-information collector before installation completes. It transmits the resulting telemetry to a Telegram endpoint.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
callback.jsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
callback.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
callback.jsView on unpkg · L1Source collects local host identity data and sends it to an external endpoint.
callback.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
callback.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
callback.jsView on unpkg · L1Package ships compressed or archive-like blobs.
starbucks-sdk-1.0.0.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
starbucks-sdk-1.0.0.tgzView on unpkgThis report applies to starbucks-sdk@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
callback.jsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
callback.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
callback.jsView on unpkg · L1Source collects local host identity data and sends it to an external endpoint.
callback.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
callback.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
callback.jsView on unpkg · L1Package ships compressed or archive-like blobs.
starbucks-sdk-1.0.0.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
starbucks-sdk-1.0.0.tgzView on unpkg