Install-time code fetches opaque executable payloads and stores them locally without integrity verification. The CLI launcher subsequently executes the downloaded payload with the caller's environment. No confirmed credential theft or AI-agent control-surface mutation appears in the inspected JavaScript.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
install.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
apex.cjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
install.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
apex.cjsView on unpkg