AUTHORISED SECURITY RESEARCH — dependency confusion proof of concept. This package was published because the name appeared in publicly served code but was unregistered on the public registry. If it is in your dependency tree, your resolver fetched an inte
npm installation triggers automatic collection of host, user, path, project metadata, and network identifiers. The package exfiltrates that data by DNS plus HTTP/HTTPS callbacks.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpreinstall automatically executes index.js during npm installation.
package.jsonView on unpkg · L10A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgSource reads consuming project's manifest and host/user/home/network identifiers.
index.jsView on unpkg · L112Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L11preinstall automatically executes index.js during npm installation.
package.jsonView on unpkg · L10Source reads consuming project's manifest and host/user/home/network identifiers.
index.jsView on unpkg · L112A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkg