This analysis was performed using vet and SafeDep Cloud Malicious Package Analysis. Integrate with GitHub using vet-action GitHub Action.
Hardcoded proxy settings ('iLoveJavaScript', port 0) suggest malicious intent, potentially leading to MitM attacks. Package is classified as malware.
The package contains hardcoded proxy settings with the hostname 'iLoveJavaScript' and port 0 in multiple files (connect.js
, state_machine.js
). This is highly suspicious and indicative of malicious intent, potentially designed to misconfigure proxy connections or redirect traffic through an unintended server, leading to a Man-in-the-Middle attack.