Skip to content

adriandersen/malicious-pre-install-package

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

9 Commits
 
 
 
 
 
 

Repository files navigation

malicious-pre-install-package

Please don't install this package.

Why?

This package is just a "private" project to showcase how easy it is to abuse the preinstall and postinstall scripts in npm. This specific package does not send any sensitive information, but it could as well send SSH keys or any other sensitive credentials.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors