Claudin — Claude Code opened to any LLM (OpenAI, Gemini, DeepSeek, Ollama, and 200+ models)
Static analysis completed at 97.0% confidence. No malicious behavior was detected; 29 low-signal pattern(s) were surfaced and cleared.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains a possible secret pattern.
dist/chunks/cli-1.1.34-v2gbtt59.mjsView on unpkg · L49Package source references child process execution.
dist/chunks/node-1.1.34-sdqnj3qm.mjsView on unpkg · L5Package source references dynamic require/import behavior.
cli-wrapper.cjsView on unpkg · L14A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/chunks/cli-1.1.34-yrk4mxjw.mjsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/chunks/watchLoop-1.1.34-tnjnpc05.mjsView on unpkg · L1Source reaches cloud instance metadata or link-local credential endpoints.
dist/chunks/cli-1.1.34-zpsaqq15.mjsView on unpkg · L1Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/chunks/index-1.1.34-mx39dxjj.mjsView on unpkg · L20This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunks/bridgeMain-1.1.34-saff9rp6.mjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunks/bridgeMain-1.1.34-saff9rp6.mjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunks/cli-1.1.34-gmaedxb1.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.34-84707tma.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.34-mhjjf878.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.34-q83yydqv.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.34-mbeaqq0q.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.34-166q8s04.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.34-7bxexffs.mjsView on unpkgHardcoded password in dist/chunks/openaiShim-1.1.34-kj2a4r19.mjs
dist/chunks/openaiShim-1.1.34-kj2a4r19.mjsView on unpkg · L11This report applies to @claudiolabs/claudin@1.1.34.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L32This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunks/bridgeMain-1.1.34-saff9rp6.mjsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunks/bridgeMain-1.1.34-saff9rp6.mjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/chunks/cli-1.1.34-gmaedxb1.mjs#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.34-84707tma.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.34-mhjjf878.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.34-q83yydqv.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.34-mbeaqq0q.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.34-166q8s04.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/cli-1.1.34-7bxexffs.mjsView on unpkgHardcoded password in dist/chunks/openaiShim-1.1.34-kj2a4r19.mjs
dist/chunks/openaiShim-1.1.34-kj2a4r19.mjsView on unpkg · L11Package contains a possible secret pattern.
dist/chunks/cli-1.1.34-v2gbtt59.mjsView on unpkg · L49Package source references child process execution.
dist/chunks/node-1.1.34-sdqnj3qm.mjsView on unpkg · L5Package source references dynamic require/import behavior.
cli-wrapper.cjsView on unpkg · L14A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/chunks/cli-1.1.34-yrk4mxjw.mjsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/chunks/watchLoop-1.1.34-tnjnpc05.mjsView on unpkg · L1Source reaches cloud instance metadata or link-local credential endpoints.
dist/chunks/cli-1.1.34-zpsaqq15.mjsView on unpkg · L1Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/chunks/index-1.1.34-mx39dxjj.mjsView on unpkg · L20