npm lifecycle hooks exfiltrate the consumer's current installation directory and host name to Discord. This occurs without a user command beyond installing the package.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe preinstall hook sends the install directory to a Discord webhook.
package.jsonView on unpkg · L7The postinstall hook sends the host name to the same external webhook.
package.jsonView on unpkg · L8This report applies to tol8t@14.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgAn npm script sends host identity through command substitution to a fixed external destination.
package.json#scripts.preinstallView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgThe preinstall hook sends the install directory to a Discord webhook.
package.jsonView on unpkg · L7The postinstall hook sends the host name to the same external webhook.
package.jsonView on unpkg · L8Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgAn npm script sends host identity through command substitution to a fixed external destination.
package.json#scripts.preinstallView on unpkg