Claudin — Claude Code opened to any LLM (OpenAI, Gemini, DeepSeek, Ollama, and 200+ models)
No confirmed malicious attack surface. The postinstall hook performs platform-specific local launcher setup within the package directory.
The AI recommended clean, but the final policy action is warn. This report does not record a matching static-policy override reason.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains a possible secret pattern.
dist/chunks/cli-1.1.16-m68wgnx0.mjsView on unpkg · L1Package source references child process execution.
dist/chunks/cli-1.1.16-x1r7521q.mjsView on unpkg · L18Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.16-x1r7521q.mjsView on unpkgPackage source references dynamic require/import behavior.
cli-wrapper.cjsView on unpkg · L14Package source references weak cryptographic algorithms.
dist/chunks/hookChains-1.1.16-9h14zpb6.mjsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/chunks/cli-1.1.16-49bqpfq6.mjsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/chunks/cli-1.1.16-49bqpfq6.mjsView on unpkg · L1Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/chunks/index-1.1.16-2rsmxhr2.mjsView on unpkg · L20This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunks/bridgeMain-1.1.16-04vqwa21.mjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunks/bridgeMain-1.1.16-04vqwa21.mjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.16-hwr77b8n.mjsView on unpkgHardcoded password in dist/chunks/openaiShim-1.1.16-8gems3mz.mjs
dist/chunks/openaiShim-1.1.16-8gems3mz.mjsView on unpkg · L11This report applies to @claudiolabs/claudin@1.1.16.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L32Package source references child process execution.
dist/chunks/cli-1.1.16-x1r7521q.mjsView on unpkg · L18Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.16-x1r7521q.mjsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunks/bridgeMain-1.1.16-04vqwa21.mjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunks/bridgeMain-1.1.16-04vqwa21.mjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.16-hwr77b8n.mjsView on unpkgHardcoded password in dist/chunks/openaiShim-1.1.16-8gems3mz.mjs
dist/chunks/openaiShim-1.1.16-8gems3mz.mjsView on unpkg · L11Package contains a possible secret pattern.
dist/chunks/cli-1.1.16-m68wgnx0.mjsView on unpkg · L1Package source references dynamic require/import behavior.
cli-wrapper.cjsView on unpkg · L14Package source references weak cryptographic algorithms.
dist/chunks/hookChains-1.1.16-9h14zpb6.mjsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/chunks/cli-1.1.16-49bqpfq6.mjsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/chunks/cli-1.1.16-49bqpfq6.mjsView on unpkg · L1Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/chunks/index-1.1.16-2rsmxhr2.mjsView on unpkg · L20