Skip to content

httptoolkit/evil-package

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

evil-package

An npm package demonstrating how packages can steal your data (but not actually doing so!)

This captures the environment variable $PLEASE_STEAL_THESE_CREDENTIALS and sends it to an evil site when the package is installed or required.

The evil site in question is evil.test - note that .test is a reserved TLD, which will never resolve, and so these requests will always fail, that's OK.

About

An npm package demonstrating how packages can steal your data (but not actually doing so!)

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published