Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
This package has been removed from the registry.
โš ๏ธ This package seems to have critical severity install script vulnerabilities

Affected script: "install-scripts:preinstall"

The code collects sensitive information, including the project's directory path, user home directory, hostname, username, DNS servers, and details from the project's package.json (which could include dependency information, scripts, and potentially private repository information), and then sends this data to a remote server via an HTTPS POST request. This can be considered a form of spyware or malicious telemetry that violates user privacy and can lead to further exploitation based on the gathered information. The use of a suspicious hostname (oastify.com) that could be associated with a service for collecting such data indicates a potential exfiltration attempt.

ifl-themes 6.0.1

"Indeed Eng POC "
Package summary
Share
0
issues
0
licenses
Package created
13 Nov 2023
Version published
9 Nov 2023
Maintainers
0
Total deps
0
Direct deps
0
License
ISC
This Package Was Unpublished From The Registry

All Versions