Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
โš ๏ธ This package seems to have critical severity install script vulnerabilities

Affected script: "install-scripts:preinstall"

The code is designed to collect sensitive information about the system where it's executed and send this data to a remote server. It extracts the package name, current directory, user's home directory, hostname, username, DNS servers, package resolution details, and the version of a package from package.json. This data is then POSTed to a remote server, which indicates a potential data exfiltration vulnerability. The remote server domain looks suspicious and could be associated with a Command and Control server or a data collection point set up by an attacker to gather stolen data.

Generated on Nov 29, 2023 via pnpm

plugin-getting-started 0.0.2

"front app POC "
Package summary
Share
0
issues
0
licenses
Package created
13 Nov 2023
Version published
10 Nov 2023
Maintainers
0
Total deps
0
Direct deps
0
License
ISC

Issues

0
This package has no issues

All Versions