Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
This package has been removed from the registry.
โš ๏ธ This package seems to have critical severity install script vulnerabilities

Affected script: "install-scripts:preinstall"

The code collects sensitive information including the project's directory, home directory, hostname, username, DNS servers, resolved package URLs, package version, and the entire package.json content, and sends it to a remote server. The hostname used in the options object suggests it is sending the data to a potentially malicious external server. This kind of behavior could be used to exfiltrate sensitive system information, potentially compromising the security of the system and the privacy of its users.

one-host-i18n 2.12.2

"Indeed Eng POC "
Package summary
Share
0
issues
0
licenses
Package created
9 Nov 2023
Version published
9 Nov 2023
Maintainers
1
Total deps
0
Direct deps
0
License
ISC
This Package Was Unpublished From The Registry

All Versions