Automatic npm lifecycle hooks transmit local host metadata to Discord. The transmissions occur before and after installation.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe preinstall hook sends the current installation directory to Discord without user interaction.
package.jsonView on unpkg · L8The postinstall hook sends the machine hostname to Discord after installation.
package.jsonView on unpkg · L9Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgAn npm script sends host identity through command substitution to a fixed external destination.
package.json#scripts.preinstallView on unpkgThis report applies to tetomood@12.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe preinstall hook sends the current installation directory to Discord without user interaction.
package.jsonView on unpkg · L8The postinstall hook sends the machine hostname to Discord after installation.
package.jsonView on unpkg · L9Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgAn npm script sends host identity through command substitution to a fixed external destination.
package.json#scripts.preinstallView on unpkg