Claudin — Claude Code opened to any LLM (OpenAI, Gemini, DeepSeek, Ollama, and 200+ models)
No confirmed attack surface was established from the inspected source. The package does have install-time launcher setup and user-invoked update and migration capabilities.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains a possible secret pattern.
dist/chunks/cli-1.1.32-yhftam6y.mjsView on unpkg · L49Package source references child process execution.
dist/chunks/cli-1.1.32-5qjjtpkh.mjsView on unpkg · L18Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.32-5qjjtpkh.mjsView on unpkgPackage source references dynamic require/import behavior.
dist/chunks/cli-1.1.32-5qjjtpkh.mjsView on unpkg · L18Package source references shell execution.
dist/chunks/cli-1.1.32-pve0ffcp.mjsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
dist/chunks/cli-1.1.32-1913x5jp.mjsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/chunks/cli-1.1.32-vf3r8a91.mjsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/chunks/cli-1.1.32-vf3r8a91.mjsView on unpkg · L1Source reaches cloud instance metadata or link-local credential endpoints.
dist/chunks/index-1.1.32-vaknvmtk.mjsView on unpkg · L1Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/chunks/index-1.1.32-dn9thxs1.mjsView on unpkg · L20This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunks/bridgeMain-1.1.32-d20ebbde.mjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunks/bridgeMain-1.1.32-d20ebbde.mjsView on unpkg · L1Source decodes a Base64-obscured HTTP endpoint at runtime.
dist/chunks/defaultActionDeps-1.1.32-nf0mf9nq.mjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunks/cache-probe-1.1.32-a9jc0rn9.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.32-9yka8m9x.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.32-aqfcrtfz.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.32-260jjrwt.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.32-6jxftegx.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.32-g5dzf2w1.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/index-1.1.32-bpzdp87c.mjsView on unpkgHardcoded password in dist/chunks/openaiShim-1.1.32-68nafznt.mjs
dist/chunks/openaiShim-1.1.32-68nafznt.mjsView on unpkg · L11This report applies to @claudiolabs/claudin@1.1.32.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.32-vf3r8a91.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L32Package source references child process execution.
dist/chunks/cli-1.1.32-5qjjtpkh.mjsView on unpkg · L18Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.32-5qjjtpkh.mjsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/chunks/index-1.1.32-vaknvmtk.mjsView on unpkg · L1Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/chunks/index-1.1.32-dn9thxs1.mjsView on unpkg · L20This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunks/bridgeMain-1.1.32-d20ebbde.mjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunks/bridgeMain-1.1.32-d20ebbde.mjsView on unpkg · L1Source decodes a Base64-obscured HTTP endpoint at runtime.
dist/chunks/defaultActionDeps-1.1.32-nf0mf9nq.mjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunks/cache-probe-1.1.32-a9jc0rn9.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.32-9yka8m9x.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.32-aqfcrtfz.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.32-260jjrwt.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.32-6jxftegx.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.32-g5dzf2w1.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/index-1.1.32-bpzdp87c.mjsView on unpkgHardcoded password in dist/chunks/openaiShim-1.1.32-68nafznt.mjs
dist/chunks/openaiShim-1.1.32-68nafznt.mjsView on unpkg · L11Package contains a possible secret pattern.
dist/chunks/cli-1.1.32-yhftam6y.mjsView on unpkg · L49Package source references dynamic require/import behavior.
dist/chunks/cli-1.1.32-5qjjtpkh.mjsView on unpkg · L18Package source references shell execution.
dist/chunks/cli-1.1.32-pve0ffcp.mjsView on unpkg · L1Source writes installer persistence such as shell profile or service configuration.
dist/chunks/cli-1.1.32-1913x5jp.mjsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/chunks/cli-1.1.32-vf3r8a91.mjsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/chunks/cli-1.1.32-vf3r8a91.mjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.32-vf3r8a91.mjsView on unpkg