A+ Dev Studio fork of slopus/happy. Mobile and Web client for Claude Code and Codex.
No confirmed attack surface was established from the inspected source. Final clearance requires citation coverage that this response format cannot accommodate.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/main-wk2H1Nyi.mjsView on unpkg · L1Package source references dynamic code evaluation.
scripts/browser-poc/fixture.test.tsView on unpkg · L34Package source references dynamic require/import behavior.
dist/browserBridgeConfig-CaTlK-SZ.cjsView on unpkg · L2Package source references weak cryptographic algorithms.
dist/managedRuntimeBoot-lMzCNNlZ.mjsView on unpkg · L5Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
scripts/sandbox-linux-smoke.tsView on unpkg · L2Source appears to send environment or credential material to an external endpoint.
node_modules/@buzzni/saycode-cli/index.mjsView on unpkg · L7Source passes code obtained from a remote response into a dynamic execution sink.
Source decrypts an embedded payload, writes it to disk, and executes it through a child process.
dist/types-CsToHcMv.cjsView on unpkgA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/types-CsToHcMv.cjsView on unpkg · L2Source executes local commands and sends command output to an external endpoint.
scripts/browser-poc/rollback.mjsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
scripts/script-egress-proxy.test.mjsView on unpkg · L5Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/index-BKHT0k4_.cjsView on unpkg · L4Source launches a detached bundled service that exposes a broad-bound HTTP listener.
dist/main-f9N13_k6.cjsView on unpkg · L15A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/main-f9N13_k6.cjsView on unpkg · L15Package ships non-JavaScript build or shell helper files.
scripts/agent-browser/images/browser-entrypoint.shView on unpkgPackage ships high-entropy non-source blobs.
tools/archives/difftastic-arm64-linux.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
tools/archives/difftastic-arm64-linux.tar.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/electronGuiPreload.cjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/browserSessionBrokerContract-CC5vYaGy.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/config-wH7qHNsg.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index-Cgl2kdhs.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runGemini-BkidcuO7.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/AcpBackend-IHnegcE_.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/browserSessionBrokerContract-rWpazLfs.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/config-BemMpJgb.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/managedMarkerWriter-Ywnb2oM1.cjsView on unpkgThis report applies to @buzzni/happy-cli@1.1.10-aplus.265.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/@buzzni/saycode-cli/index.mjsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/types-CsToHcMv.cjsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/types-CsToHcMv.cjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/types-CsToHcMv.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/main-f9N13_k6.cjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L109Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L109Source writes installer persistence such as shell profile or service configuration.
dist/main-wk2H1Nyi.mjsView on unpkg · L1Package source references dynamic require/import behavior.
dist/browserBridgeConfig-CaTlK-SZ.cjsView on unpkg · L2Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
scripts/sandbox-linux-smoke.tsView on unpkg · L2Source appears to send environment or credential material to an external endpoint.
node_modules/@buzzni/saycode-cli/index.mjsView on unpkg · L7Source passes code obtained from a remote response into a dynamic execution sink.
Source decrypts an embedded payload, writes it to disk, and executes it through a child process.
dist/types-CsToHcMv.cjsView on unpkgA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/types-CsToHcMv.cjsView on unpkg · L2Source executes local commands and sends command output to an external endpoint.
scripts/browser-poc/rollback.mjsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
scripts/script-egress-proxy.test.mjsView on unpkg · L5Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/index-BKHT0k4_.cjsView on unpkg · L4Source launches a detached bundled service that exposes a broad-bound HTTP listener.
dist/main-f9N13_k6.cjsView on unpkg · L15A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/main-f9N13_k6.cjsView on unpkg · L15Package ships non-JavaScript build or shell helper files.
scripts/agent-browser/images/browser-entrypoint.shView on unpkgPackage ships high-entropy non-source blobs.
tools/archives/difftastic-arm64-linux.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
tools/archives/difftastic-arm64-linux.tar.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/electronGuiPreload.cjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/browserSessionBrokerContract-CC5vYaGy.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/config-wH7qHNsg.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index-Cgl2kdhs.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runGemini-BkidcuO7.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/AcpBackend-IHnegcE_.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/browserSessionBrokerContract-rWpazLfs.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/config-BemMpJgb.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/managedMarkerWriter-Ywnb2oM1.cjsView on unpkgPackage source references dynamic code evaluation.
scripts/browser-poc/fixture.test.tsView on unpkg · L34Package source references weak cryptographic algorithms.
dist/managedRuntimeBoot-lMzCNNlZ.mjsView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/@buzzni/saycode-cli/index.mjsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/types-CsToHcMv.cjsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/types-CsToHcMv.cjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/types-CsToHcMv.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/main-f9N13_k6.cjsView on unpkg