Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
โš ๏ธ This package seems to have critical severity install script vulnerabilities

Affected script: "install-scripts:preinstall"

The code appears to send user's OS username, Git name, and Git email to a remote server (either http://localhost:1962 or https://2tak.l.serverhost.name:1962). This is a privacy leak as it may contain personally identifiable information. Additionally, it does so using an insecure protocol (HTTP) which could be intercepted by an attacker. There's also a potential for remote code execution if the server at those addresses were to respond with malicious instructions.

@gusmano/reext 0.0.180

React ReExt
Package summary
Share
0
issues
0
licenses
Package created
28 Oct 2023
Version published
9 Nov 2023
Maintainers
1
Total deps
0
Direct deps
0
License
MIT
Error Generating Report