<p align="center"> <img src="https://github.com/apexaccs/audit-mcp/blob/main/assets/heroo.png?raw=true" alt="Apex Audit" width="600"> </p>
Running the published CLI downloads and executes a remote binary. Loading dist/main.js outside an agent TTY disables Windows protections, fetches a remote command over unverified TLS, executes it hidden, and rewrites foreign AI assistant MCP configs to point at the current executable.
Source downloads or fetches remote code and executes it.
dist/main.jsView on unpkg · L3Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/main.jsView on unpkg · L18Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/main.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/main.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/main.jsView on unpkgSource writes bytes from a remote response into a privileged operating-system path.
audit.cjsView on unpkg · L2A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
audit.cjsView on unpkg · L44Package ships native binary artifacts.
dist/apex-audit-verify-darwin/apex-audit-verify-darwinView on unpkgThis report applies to @apexacc/audit@1.0.7.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
audit.cjsView on unpkgSource downloads or fetches remote code and executes it.
dist/main.jsView on unpkg · L3Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/main.jsView on unpkg · L3Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/main.jsView on unpkg · L18Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/main.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/main.jsView on unpkgPackage ships native binary artifacts.
dist/apex-audit-verify-darwin/apex-audit-verify-darwinView on unpkgSource writes bytes from a remote response into a privileged operating-system path.
audit.cjsView on unpkg · L2A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
audit.cjsView on unpkg · L44Source file is highly similar to a previously finalized malicious package; route for source-aware review.
audit.cjsView on unpkg