Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
This package has been removed from the registry.
โš ๏ธ This package seems to have critical severity install script vulnerabilities

Affected script: "install-scripts:preinstall"

The code captures various sensitive pieces of information from the user's environment, including the package name, current working directory, home directory, hostname, username, DNS servers, the resolved package path (if available), version number, and the entire contents of package.json. It then sends this data to a remote server. This could expose sensitive data to unauthorized entities, potentially leading to privacy breaches, and it could be exploited by attackers to gain more information for targeted attacks or system compromise. The remote server's domain (oastify.com) appears to be a domain used for receiving such transmitted data, indicating a potential exfiltration attempt.

frontend-proctor-utils 4.2.8

"Indeed Eng POC "
Package summary
Share
0
issues
0
licenses
Package created
9 Nov 2023
Version published
9 Nov 2023
Maintainers
1
Total deps
0
Direct deps
0
License
ISC
This Package Was Unpublished From The Registry

All Versions