Runtime for the boxes.dev CLI. Install @boxes-dev/dvb to use the CLI.
No confirmed active attack surface was established. A binary archive in the published boxes-mosh directory could not be source-inspected, preventing a clean verdict.
Source downloads or fetches remote code and executes it.
dist/bin/dvbd.mjsView on unpkg · L7A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bin/dvbd.mjsView on unpkg · L7Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bin/dvbd.mjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bin/dvbd.mjsView on unpkg · L7A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/bin/dvbd.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/dvbd.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/bin/dvbd.mjsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bin/dvbd.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/bin/dvbd.mjsView on unpkgPackage ships native binary artifacts.
dist/boxes-mosh/linux-arm64/mosh-clientView on unpkgPackage ships high-entropy non-source blobs.
dist/boxes-mosh/linux-arm64/notices.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
dist/boxes-mosh/linux-arm64/notices.tar.gzView on unpkgThis report applies to @boxes-dev/dvb-runtime@1.0.1037.
See version security history for other recorded verdicts.
Evidence last updated: .
Source downloads or fetches remote code and executes it.
dist/bin/dvbd.mjsView on unpkg · L7A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bin/dvbd.mjsView on unpkg · L7Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bin/dvbd.mjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bin/dvbd.mjsView on unpkg · L7A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/bin/dvbd.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/dvbd.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/bin/dvbd.mjsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bin/dvbd.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/bin/dvbd.mjsView on unpkgPackage ships native binary artifacts.
dist/boxes-mosh/linux-arm64/mosh-clientView on unpkgPackage ships high-entropy non-source blobs.
dist/boxes-mosh/linux-arm64/notices.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
dist/boxes-mosh/linux-arm64/notices.tar.gzView on unpkg