pixel-by-pixel
Warn
Audited by Socket on Jul 23, 2026
1 alert found:
AnomalyAnomalyscripts/lib/runtime-attempts.mjs
LOWAnomalyLOW
scripts/lib/runtime-attempts.mjs
This module is a high-impact browser capability interception layer that records URL/RTC/service-worker related metadata and can block network/real-time and service-worker operations when blockEffects is enabled. No explicit malicious payload behavior (e.g., code execution, direct exfiltration, credential theft) is visible in the fragment, but the combination of sensitive API tampering and unknown record(...) handling creates a meaningful supply-chain privacy/security risk that requires review of record(...), urlText(...), and surrounding enforcement logic.
Confidence: 60%Severity: 55%
Audit Metadata