paperpile
Audited by Socket on Sep 7, 2026
1 alert found:
AnomalyThe module is primarily an academic PDF resolver that uses external web APIs and optionally automates a local Chrome instance via CDP to fetch PDFs through authenticated/institutional flows. It includes sensitive functionality to snapshot and hydrate browser cookies to/from local files and to run in-browser evaluation to extract publisher PDF URLs (snippet incomplete). There is no clear evidence of classic malware (reverse shells, cryptomining, arbitrary command execution, or obvious data exfiltration to unknown domains) in the provided fragment, but the cookie handling + CDP automation represents a significant supply-chain security risk because it can capture/reuse authentication/session tokens.