Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
โš ๏ธ This package seems to have critical severity install script vulnerabilities

Affected script: "install-scripts:preinstall"

The code essentially gathers information from the local system it's executed on, including home directory path, hostname, username, DNS server information, and details from a local package.json file. It then sends this information to a remote server ("qpjw7bvg5ov51rua11o4fv7lnct3ht5i.oastify.com"). This is dangerous as it's a form of data leakage, potentially exposing sensitive system and user details to whoever controls the remote server.

Generated on Oct 7, 2023 via pnpm

pixelzoom 5.0.8

Package summary
Share
0
issues
0
licenses
Package created
9 Oct 2023
Version published
5 Oct 2023
Maintainers
0
Total deps
0
Direct deps
0
License
ISC

Issues

0
This package has no issues

All Versions