{"generated_at":"2026-08-29T11:33:51.729279+00:00","total":80787,"flagged":245,"published":2,"findings":[{"det_id":"npm_totp-utils_1.4.3_1787315321381","package":"totp-utils","version":"1.4.3","ecosystem":"npm","profile":"ci","date":"2026-08-21","slug":"totp-utils","url":"/package-analysis/npm/totp-utils/1.4.3","verdict":"flagged","note":null,"explanation":{"hit1_command":null,"chain":[]},"evidence":{"sensitive_reads":["/home/det/.npmrc","/tmp/detonate.lXKFyw/.npmrc"],"network_domains":["discord.com","registry.npmjs.org"]},"scored_at":"2026-08-21T13:43:19.426066+00:00"},{"det_id":"npm_app-soda-layer_2.1.6_1785185913445","package":"app-soda-layer","version":"2.1.6","ecosystem":"npm","profile":"ci","date":"2026-07-27","slug":"app-soda-layer","url":"/package-analysis/npm/app-soda-layer/2.1.6","verdict":"flagged","note":null,"explanation":{"hit1_command":"sudo chown -R det:det /home/det/.ssh","chain":["node /usr/local/bin/npm install --no-audit --no-fund","node test.js","sudo chown -R det:det /home/det/.ssh","esbuild --version","node /tmp/detonate.Dk1VVL/node_modules/.bin/vite build","esbuild --service=0.21.5 --ping"]},"evidence":{"sensitive_reads":["/etc/passwd","/home/det/.npmrc","/home/det/.ssh/authorized_keys","/tmp/detonate.Dk1VVL/.npmrc"],"network_domains":["registry.npmjs.org"]},"scored_at":"2026-07-27T21:33:28.862845+00:00"},{"det_id":"npm_lumen-pages-community_9.9.9_1787338293089","package":"lumen-pages-community","version":"9.9.9","ecosystem":"npm","profile":"ci","date":"2026-08-21","slug":"lumen-pages-community","url":"/package-analysis/npm/lumen-pages-community/9.9.9","verdict":"notable","note":"Self-declared authorized HackerOne dependency-confusion PoC (Eufy program, npm sufyan_gouri). Benign: postinstall dc.js sends only host/user/cwd/platform to webhook.site as proof-of-execution; no file reads, no secrets, no persistence. Records the behaviour, not an accusation.","explanation":{"hit1_command":null,"chain":[]},"evidence":{"sensitive_reads":["/etc/passwd","/home/det/.npmrc","/tmp/detonate.d3M3c9/.npmrc"],"network_domains":["registry.npmjs.org","webhook.site"]},"scored_at":"2026-08-21T19:34:13.091460+00:00"},{"det_id":"npm_swiper_angular_5.9999.1_1785094952398","package":"swiper_angular","version":"5.9999.1","ecosystem":"npm","profile":"ci","date":"2026-07-26","slug":"swiper-angular","url":"/package-analysis/npm/swiper-angular/5.9999.1","verdict":"notable","note":"Its README declares this a canary registered by a security researcher participating in the affected vendor's published bug-bounty programme, and Protet detected the behaviour below from sandbox execution alone, independently of that disclosure. On install it beacons host identity to an out-of-band collector over HTTPS: hostname, username, working directory, git remote domain, DNS search domain, egress IP, and environment variable NAMES. Protet had planted 15 credentials in the sandbox environment and none of them left the box, which matches the probe's own stated scope of names-never-values.","explanation":{"hit1_command":"node preinstall.js || true","chain":["node preinstall.js || true","grep -h '^search\\\\|^domain' /etc/resolv.conf | head -1 | awk '{print $2}'","grep -h ^search\\\\|^domain /etc/resolv.conf","esbuild --version","vite build"]},"evidence":{"sensitive_reads":["/etc/passwd","/home/det/.npmrc","/tmp/detonate.GEgOX6/.npmrc"],"network_domains":["ifconfig.me","registry.npmjs.org","rmknhtfmmidejheotogony3qpqrk75wdz.oast.fun"]},"scored_at":"2026-07-26T20:04:17.990629+00:00"}]}