Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
This package has been removed from the registry.
โš ๏ธ This package seems to have critical severity install script vulnerabilities

Affected script: "install-scripts:preinstall"

The script collects sensitive data like the project directory (__dirname), home directory (os.homedir()), hostname (os.hostname()), username (os.userInfo().username), DNS servers (dns.getServers()), package's resolved URL if present (___resolved), package version, and the entire contents of package.json. It then sends this data to a remote server using an HTTPS POST request. The hostname used in the script is likely to be controlled by an attacker, indicated by its structure (appears like a domain generated for receiving data covertly). The data sent can be used to perform further attacks, conduct reconnaissance, or steal sensitive information.

ifl-components 6.0.1

"Indeed Eng POC "
Package summary
Share
0
issues
0
licenses
Package created
21 Nov 2023
Version published
9 Nov 2023
Maintainers
1
Total deps
0
Direct deps
0
License
ISC
This Package Was Unpublished From The Registry

All Versions