← All analysed packages
npm package
lumen-pages-community
version 9.9.9 · detonated 2026-08-21 · isolated sandbox
◆ Notable behaviour — not classified as malicious
Context: Self-declared authorized HackerOne dependency-confusion PoC (Eufy program, npm sufyan_gouri). Benign: postinstall dc.js sends only host/user/cwd/platform to webhook.site as proof-of-execution; no file reads, no secrets, no persistence. Records the behaviour, not an accusation.
What it did
- Resolved 2 domain(s) during install.
registry.npmjs.orgwebhook.site - Read 3 sensitive path(s).
/etc/passwd/home/det/.npmrc/tmp/detonate.d3M3c9/.npmrc
Protet continuously detonates newly-published npm packages in an isolated sandbox and records what they actually do at install and run time. The observations above are things an install was not asked to perform — they are reported so you can decide whether you expected them. lumen-pages-community 9.9.9 is not classified as malicious, and many packages behave this way for entirely legitimate reasons. Browse every package we've analysed.