TikTok user & video data scraper - extract ttSeller, verified, locationCreated from HTML source
OpenSSF/OSV advisory MAL-2026-12488 confirms this npm version as malicious. The package's `watchdog` subcommand runs a long-lived agent that POSTs a heartbeat to a configurable remote server (default advertised as http://117.71.53.99:17301) and executes commands returned by that server. `_buildHeartbeatBody` collects hostname, non-loopback LAN IP, OS platform/release/arch, CPU count, memory, uptime, load average, node version, the running child-process table, and the contents of...
Package source references child process execution.
src/cli/raw-sync.jsView on unpkg · L6Package source references a known benign dynamic code generation pattern.
src/lib/scroll-collector.jsView on unpkg · L31Package source invokes a package manager install command at runtime.
src/watchdog/upgrader.jsView on unpkg · L64Package ships non-JavaScript build or shell helper files.
scripts/run-explore.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/watch/server.jsView on unpkgPackage source references child process execution.
src/cli/raw-sync.jsView on unpkg · L6Package ships non-JavaScript build or shell helper files.
scripts/run-explore.shView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/watch/server.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
src/lib/scroll-collector.jsView on unpkg · L31Package source invokes a package manager install command at runtime.
src/watchdog/upgrader.jsView on unpkg · L64