Demo package for a supply-chain security conference talk. The postinstall script reads the machine's hosts file (/etc/hosts) at install time to show what npm runs with no approval - locally only, sends no data, and has no dependencies.
@indie_rok/[email protected] low health (55/100) — consider alternatives
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/npm/@indie_rok/demo-suspicious-packageFirst published · 2026-08-18T10:10:21.252Z
Last updated · 2026-08-18T14:54:57.922Z