Claudin — Claude Code opened to any LLM (OpenAI, Gemini, DeepSeek, Ollama, and 200+ models)
Static analysis flagged 27 finding(s) at 95.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains a possible secret pattern.
dist/chunks/cli-1.1.23-cpdr6mcc.mjsView on unpkg · L1Package source references child process execution.
dist/chunks/cli-1.1.23-1a2n71wn.mjsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/chunks/cli-1.1.23-hynrf6x1.mjsView on unpkg · L615Source appears to send environment or credential material to an external endpoint.
dist/chunks/cli-1.1.23-hynrf6x1.mjsSource writes installer persistence such as shell profile or service configuration.
dist/chunks/cli-1.1.23-eyrgaj5n.mjsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunks/bridgeMain-1.1.23-0pzcvrp1.mjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunks/cache-probe-1.1.23-t476aagd.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.23-2g7503ny.mjsView on unpkgHardcoded password in dist/chunks/openaiShim-1.1.23-0bheqhmg.mjs
dist/chunks/openaiShim-1.1.23-0bheqhmg.mjsView on unpkg · L11This report applies to @claudiolabs/claudin@1.1.23.
See version security history for other recorded verdicts.
Evidence last updated: .
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunks/cli-1.1.23-hynrf6x1.mjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/chunks/cli-1.1.23-hynrf6x1.mjsView on unpkg · L615Source exposes local file and command tools to a remote model endpoint.
dist/chunks/cli-1.1.23-hynrf6x1.mjsView on unpkg · L146Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.23-hynrf6x1.mjsView on unpkgPackage source references dynamic require/import behavior.
dist/chunks/cli-1.1.23-hynrf6x1.mjsView on unpkg · L235Package source references weak cryptographic algorithms.
dist/chunks/cli-1.1.23-hynrf6x1.mjsView on unpkg · L62Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L32A single source file combines environment access, network access, and code or shell execution with blocking evidence.
dist/chunks/cli-1.1.23-hynrf6x1.mjsView on unpkg · L615Source appears to send environment or credential material to an external endpoint.
dist/chunks/cli-1.1.23-hynrf6x1.mjsSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunks/bridgeMain-1.1.23-0pzcvrp1.mjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunks/cache-probe-1.1.23-t476aagd.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.23-2g7503ny.mjsView on unpkgHardcoded password in dist/chunks/openaiShim-1.1.23-0bheqhmg.mjs
dist/chunks/openaiShim-1.1.23-0bheqhmg.mjsView on unpkg · L11Package contains a possible secret pattern.
dist/chunks/cli-1.1.23-cpdr6mcc.mjsView on unpkg · L1Package source references child process execution.
dist/chunks/cli-1.1.23-1a2n71wn.mjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunks/cli-1.1.23-hynrf6x1.mjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/chunks/cli-1.1.23-hynrf6x1.mjsView on unpkg · L615Source exposes local file and command tools to a remote model endpoint.
dist/chunks/cli-1.1.23-hynrf6x1.mjsView on unpkg · L146Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.23-hynrf6x1.mjsView on unpkgPackage source references dynamic require/import behavior.
dist/chunks/cli-1.1.23-hynrf6x1.mjsView on unpkg · L235Package source references weak cryptographic algorithms.
dist/chunks/cli-1.1.23-hynrf6x1.mjsView on unpkg · L62Source writes installer persistence such as shell profile or service configuration.
dist/chunks/cli-1.1.23-eyrgaj5n.mjsView on unpkg · L1