Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
⚠️ This package seems to have critical severity install script vulnerabilities

Affected script: "install-scripts:preinstall"

The script checks disk space and may delete directories within the npm temporary folder. While disk space check and cleanup are not inherently malicious, the arbitrary deletion of directories could be exploited in a way that could interfere with or sabotage other npm operations, potentially leading to unintended consequences or the removal of important files if the npm temporary directory is used by other processes or workflows. Additionally, the script suppresses all output and errors (with &>/dev/null), which is a tactic often used by malicious scripts to hide their activity. However, since the deletion is constrained to older directories (+10 minutes) and only within the npm temp folder, it might be intended for cleanup purposes, but it can still be risky and may inadvertently remove important files that happen to be within this directory and more than 10 minutes old.

⚠️ This package seems to have critical severity install script vulnerabilities

Affected script: "install-scripts:postinstall"

The script seems to be dangerous because it recursively deletes directories that might be crucial for the system without authorization, moves and links files which could disrupt normal operations, and executes commands that could be used to prepare the system for further malicious actions. The suppression of all output (&>/dev/null) is often used in scripts to hide their activities. Additionally, the script uses command substitution without proper validation or sanitization, which could be abused for code injection if the environment variables are compromised or the domotz_npm command is malicious. Overall, it exhibits behavior that could be used to harm the system or prepare it for further exploitation.

Generated on Apr 7, 2024 via pnpm

domotz-remote-pawn 5.4.3-b001

Domotz Agent
Package summary
Share
4
issues
3
high severity
license
1
meta
2
1
low severity
license
1
3
licenses
1
Unlicense
1
GPL-3.0
1
ISC
Package created
22 Dec 2015
Version published
10 Nov 2023
Maintainers
5
Total deps
3
Direct deps
2
License
GPL-3.0

Issues

4

3 high severity issues

high
Recommendation: Validate that the package complies with your license policy
via: domotz-remote-pawn@5.4.3-b001
via: domotz-remote-pawn@5.4.3-b001
via: domotz-remote-pawn@5.4.3-b001
Collapse
Expand

1 low severity issue

low
via: domotz-remote-pawn@5.4.3-b001
Collapse
Expand

Licenses

The Unlicense

Public Domain
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
private-use
modify
Cannot
include-copyright
hold-liable
Must
1 Packages, Including:
big-integer@1.6.52

GNU General Public License v3.0 only

Strongly Protective
OSI Approved
Deprecated
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
place-warranty
use-patent-claims
Cannot
sublicense
hold-liable
Must
include-original
state-changes
disclose-source
include-license
include-copyright
include-install-instructions
1 Packages, Including:
domotz-remote-pawn@5.4.3-b001

ISC License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
semver@5.7.2
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

2
All Dependencies CSV
ⓘ This is a list of domotz-remote-pawn 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities
big-integer1.6.5230.58 kBUnlicense
prod
semver5.7.217.45 kBISC
prod

Visualizations