Home
Docs
GitHub
Pricing
Blog
Log In

Run Sandworm Audit for your App

Get started
Hold on, we're currently generating a fresh version of this report
⚠️ This package seems to have critical severity install script vulnerabilities

Affected script: "install-scripts:preinstall"

The code provided performs a series of actions that configure a persistent and stealthy method for collecting clipboard data and sending it to a remote server. It first creates a VBScript file that will run on system startup. This VBScript is configured to execute a batch file in the background. The batch file then executes a PowerShell script, bypassing the execution policy. This PowerShell script monitors the clipboard content, posting it every second to a remote server. Such behavior is characteristic of keyloggers or information-stealing malware and poses a significant security threat due to the potential disclosure of sensitive information copied to the clipboard.

Generated on Apr 24, 2024 via pnpm

querystring-chain 0.2.6

Node's querystring module for all engines.
Package summary
Share
1
issue
1
high severity
meta
1
1
license
1
MIT
Package created
2 Oct 2023
Version published
10 Nov 2023
Maintainers
1
Total deps
1
Direct deps
0
License
MIT

Issues

1

1 high severity issue

high
via: querystring-chain@0.2.6
Collapse
Expand

Licenses

MIT License

Permissive
OSI Approved
This is a human-readable summary of (and not a substitute for) the license. Disclaimer.
Can
commercial-use
modify
distribute
sublicense
private-use
Cannot
hold-liable
Must
include-copyright
include-license
1 Packages, Including:
querystring-chain@0.2.6
Disclaimer

This deed highlights only some of the key features and terms of the actual license. It is not a license and has no legal value. You should carefully review all of the terms and conditions of the actual license before using the licensed material.

Sandworm is not a law firm and does not provide legal services. Distributing, displaying, or linking to this deed or the license that it summarizes does not create a lawyer-client or any other relationship.

Direct Dependencies

0
All Dependencies CSV
β“˜ This is a list of querystring-chain 's direct dependencies. Data on all dependencies, including transitive ones, is available via CSV download.
NameVersionSizeLicenseTypeVulnerabilities

Visualizations

All Versions