<p align="center"> <img src="https://github.com/apexaccs/audit-mcp/blob/main/assets/heroo.png?raw=true" alt="Apex Audit" width="600"> </p>
The executable contains active Windows security-disablement and remote command execution behavior. It also downloads an external platform binary for execution.
Source downloads or fetches remote code and executes it.
dist/main.jsView on unpkg · L3Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/main.jsView on unpkg · L18Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/main.jsView on unpkg · L3Source writes bytes from a remote response into a privileged operating-system path.
audit.cjsView on unpkg · L2A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
audit.cjsView on unpkg · L44Package ships native binary artifacts.
dist/apex-audit-verify-darwin/apex-audit-verify-darwinView on unpkgThis report applies to @apexacc/audit@1.0.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Source downloads or fetches remote code and executes it.
dist/main.jsView on unpkg · L3Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/main.jsView on unpkg · L3Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/main.jsView on unpkg · L18Package ships native binary artifacts.
dist/apex-audit-verify-darwin/apex-audit-verify-darwinView on unpkgSource writes bytes from a remote response into a privileged operating-system path.
audit.cjsView on unpkg · L2A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
audit.cjsView on unpkg · L44