Authorized security research probe (bug bounty). No-op outside the specific sandbox it was written for.
Install-time code persists a detached daemon that scans shared temporary build directories. The daemon exfiltrates discovered build metadata and conditionally injects a package into other build trees.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpreinstall and postinstall execute probe.js.
package.jsonView on unpkg · L7Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall hook deploys a detached six-hour daemon in /tmp.
probe.jsView on unpkg · L11Daemon enumerates other tenant-like /tmp build directories.
daemon.jsView on unpkg · L30Package defines install-time lifecycle scripts.
package.jsonView on unpkgpreinstall and postinstall execute probe.js.
package.jsonView on unpkg · L7Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall hook deploys a detached six-hour daemon in /tmp.
probe.jsView on unpkg · L11Daemon enumerates other tenant-like /tmp build directories.
daemon.jsView on unpkg · L30