Loading npm security reports…
The postinstall entrypoint contains a host-fingerprinting exfiltration attempt, but the supplied JavaScript is syntactically invalid and cannot run. It is an inert staged payload carrier rather than a functioning install-time attack.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgSource collects local host identity data and sends it to an external endpoint.
index.jsView on unpkg · L2A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgSource collects local host identity data and sends it to an external endpoint.
index.jsView on unpkg · L2A manifest entrypoint or package-local install chain reaches a fixed external POST callback.
index.jsView on unpkg