TikTok user & video data scraper - extract ttSeller, verified, locationCreated from HTML source
OpenSSF/OSV advisory MAL-2026-12488 confirms this npm version as malicious. The package's `tt-help watchdog` subcommand starts a long-running agent that POSTs heartbeats to a remote server (default hardcoded to http://117.71.53.99:17301, referenced in src/lib/constants.js and the README/run-explore examples) and executes commands returned in the response. In WatchdogAgent, syncCommands maps entries from the server's `commands` array into child_process.spawn(command, { shell: true }) via...
Package source references child process execution.
src/cli/raw-sync.jsView on unpkg · L6Package source references a known benign dynamic code generation pattern.
src/lib/scroll-collector.jsView on unpkg · L31Package source invokes a package manager install command at runtime.
src/watchdog/upgrader.jsView on unpkg · L62Package ships non-JavaScript build or shell helper files.
scripts/run-explore.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/watch/server.jsView on unpkgPackage source references child process execution.
src/cli/raw-sync.jsView on unpkg · L6Package ships non-JavaScript build or shell helper files.
scripts/run-explore.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/watch/server.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
src/lib/scroll-collector.jsView on unpkg · L31Package source invokes a package manager install command at runtime.
src/watchdog/upgrader.jsView on unpkg · L62