Runtime for the boxes.dev CLI. Install @boxes-dev/dvb to use the CLI.
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Package source references child process execution.
dist/bin/dvbd.mjsView on unpkg · L46839Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bin/dvbd.mjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bin/dvbd.mjsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/dvbd.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/bin/dvbd.mjsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/bin/dvbd.mjsView on unpkg · L19277Package ships native binary artifacts.
dist/boxes-mosh/linux-arm64/mosh-clientView on unpkgPackage ships high-entropy non-source blobs.
dist/boxes-mosh/linux-arm64/notices.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
dist/boxes-mosh/linux-arm64/notices.tar.gzView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bin/dvb.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/bin/dvb.mjsView on unpkgThis report applies to @boxes-dev/dvb-runtime@1.0.1052.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
dist/bin/dvbd.mjsView on unpkg · L46839Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bin/dvbd.mjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bin/dvbd.mjsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bin/dvbd.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/bin/dvbd.mjsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/bin/dvbd.mjsView on unpkg · L19277Package ships native binary artifacts.
dist/boxes-mosh/linux-arm64/mosh-clientView on unpkgPackage ships high-entropy non-source blobs.
dist/boxes-mosh/linux-arm64/notices.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
dist/boxes-mosh/linux-arm64/notices.tar.gzView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bin/dvb.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/bin/dvb.mjsView on unpkg