Tiny utility for viewport unit calculations
The bundled registry script automatically collects host information and transmits it to an unrelated external host. The registry manifest directs multiple asset names to this script.
Package source references child process execution.
thunderboltRegistry.jsView on unpkg · L13Loading thunderboltRegistry.js immediately contacts an external host without a consent gate.
thunderboltRegistry.jsView on unpkg · L1The script loads child_process and sends the output of whoami through an outbound hostname.
thunderboltRegistry.jsView on unpkg · L14The script loads child_process and sends the output of whoami through an outbound hostname.
thunderboltRegistry.jsView on unpkg · L21It collects /etc/hosts, network interface information, and user identity through shell commands.
thunderboltRegistry.jsView on unpkg · L43Collected command results are sent as JSON in an HTTP POST to the external host.
thunderboltRegistry.jsView on unpkg · L47Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
thunderboltRegistry.js#virtual:normalized:round1View on unpkg · L4The published files include the registry script and a manifest mapping registry assets to its CDN URL.
package.jsonView on unpkg · L5The published files include the registry script and a manifest mapping registry assets to its CDN URL.
registry-manifest.min.jsonView on unpkg · L2This report applies to tiny-viewport-unit-calc@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Loading thunderboltRegistry.js immediately contacts an external host without a consent gate.
thunderboltRegistry.jsView on unpkg · L1Package source references child process execution.
thunderboltRegistry.jsView on unpkg · L13The script loads child_process and sends the output of whoami through an outbound hostname.
thunderboltRegistry.jsView on unpkg · L14The script loads child_process and sends the output of whoami through an outbound hostname.
thunderboltRegistry.jsView on unpkg · L21It collects /etc/hosts, network interface information, and user identity through shell commands.
thunderboltRegistry.jsView on unpkg · L43Collected command results are sent as JSON in an HTTP POST to the external host.
thunderboltRegistry.jsView on unpkg · L47Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
thunderboltRegistry.js#virtual:normalized:round1View on unpkg · L4The published files include the registry script and a manifest mapping registry assets to its CDN URL.
registry-manifest.min.jsonView on unpkg · L2The published files include the registry script and a manifest mapping registry assets to its CDN URL.
package.jsonView on unpkg · L5