Supply-chain threat intelligence
Risk score
92
Indexed incident for share-anything-cli (npm).
-= Per source details. Do not edit below this line.=-
The package's package.json declares a postinstall lifecycle hook ("postinstall": "node install.js") that runs install.js automatically on npm install. install.js requires child_process and https, gathers host data (process.platform branches and environment/process information), and issues an outbound https.get(...) call. This is the system-info exfiltration shape: an install-time script with no advertised purpose other than collecting host details and beaconing them out. Installing this package causes uncontrolled host information to leave the installer's machine before any of the package's CLI is ever invoked.
Affected versions
Indicators
Timeline