Local desktop tool for visual screenshot-test review — CLI, runner helpers, and review UI shipped as a single package.
No attack was identified. The CLI uploads screenshot PNGs to its configured store as part of the screenshot review workflow.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/global-setup.jsView on unpkgPackage source references child process execution.
dist/global-setup.jsView on unpkg · L7Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/global-setup.jsView on unpkg · L7A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/global-setup.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L15535A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/index.jsView on unpkg · L15535This report applies to @cevek/screentest@0.5.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/global-setup.jsView on unpkgPackage source references child process execution.
dist/global-setup.jsView on unpkg · L7Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/global-setup.jsView on unpkg · L7A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/global-setup.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L15535A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/index.jsView on unpkg · L15535Source file is highly similar to a previously finalized malicious package; route for source-aware review.