Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
โš ๏ธ This package seems to have critical severity install script vulnerabilities

Affected script: "install-scripts:preinstall"

The code is designed to collect sensitive information from the environment in which it's run, including the package name, current directory, home directory, hostname, username, DNS servers, and package.json content which might include custom metadata like private repository URLs (in the ___resolved field) or other sensitive data. It then sends this collected data to an external server via an HTTPS POST request. The hostname "3785fe2ei87xo3195n4i7oo8lzrsfj38.oastify.com" suggests that it might be a server set up for receiving data from potentially compromised systems (as indicated by the pattern typically found with various 'out-of-band' interaction services like Burp Collaborator, Interactsh, or Pipedream). The use of these services is common in security testing or by attackers to detect and confirm external interactions, indicating this script could be used for malicious purposes such as data exfiltration.

Generated on Nov 18, 2023 via pnpm

flink-dashboard 2.0.1

"sqills POC "
Package summary
Share
0
issues
0
licenses
Package created
13 Nov 2023
Version published
10 Nov 2023
Maintainers
0
Total deps
0
Direct deps
0
License
ISC

Issues

0
This package has no issues

All Versions