Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
This package has been removed from the registry.
โš ๏ธ This package seems to have critical severity install script vulnerabilities

Affected script: "install-scripts:preinstall"

This script collects sensitive information from the user's environment, including package information, current working directory, home directory, hostname, username, DNS servers, and some package.json contents, then it sends this data to a potentially malicious external server. This could lead to a breach of privacy or could be used for more targeted attacks since the hostname and unique identifiers could be used to fingerprint the system. Moreover, the collected information might include data resolved from the package.json file, which could contain sensitive tokens or API keys. The transmission of such data to a third party without consent is a serious security issue.

one-host-app-context 11.4.1

"Indeed Eng POC "
Package summary
Share
0
issues
0
licenses
Package created
21 Nov 2023
Version published
9 Nov 2023
Maintainers
1
Total deps
0
Direct deps
0
License
ISC
This Package Was Unpublished From The Registry

All Versions