Runtime for the boxes.dev CLI. Install @boxes-dev/dvb to use the CLI.
No install-time attack was established. The package is a user-invoked CLI and daemon bundle. The required mosh notices archive could not be cited because it contains no complete printable excerpt.
Source downloads or fetches remote code and executes it.
dist/bin/dvbd.mjsView on unpkg · L7A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bin/dvbd.mjsView on unpkg · L7Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bin/dvbd.mjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bin/dvbd.mjsView on unpkg · L7A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/bin/dvbd.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/dvbd.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/bin/dvbd.mjsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bin/dvbd.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/bin/dvbd.mjsView on unpkgPackage ships native binary artifacts.
dist/boxes-mosh/linux-arm64/mosh-clientView on unpkgPackage ships high-entropy non-source blobs.
dist/boxes-mosh/linux-arm64/notices.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
dist/boxes-mosh/linux-arm64/notices.tar.gzView on unpkgThis report applies to @boxes-dev/dvb-runtime@1.0.1038.
See version security history for other recorded verdicts.
Evidence last updated: .
Source downloads or fetches remote code and executes it.
dist/bin/dvbd.mjsView on unpkg · L7A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bin/dvbd.mjsView on unpkg · L7Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bin/dvbd.mjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bin/dvbd.mjsView on unpkg · L7A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/bin/dvbd.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/dvbd.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/bin/dvbd.mjsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bin/dvbd.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/bin/dvbd.mjsView on unpkgPackage ships native binary artifacts.
dist/boxes-mosh/linux-arm64/mosh-clientView on unpkgPackage ships high-entropy non-source blobs.
dist/boxes-mosh/linux-arm64/notices.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
dist/boxes-mosh/linux-arm64/notices.tar.gzView on unpkg