Standalone clawd daemon — Claude Code (and future Codex) session server over WebSocket
At explicit daemon/tunnel runtime, the package can download and execute an external FRPC binary without verifying its integrity. It also enables log shipping by default and propagates owner Anthropic credentials to guest Claude sessions.
Package source references child process execution.
dist/dispatch/mcp-server.cjsView on unpkg · L21112Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/dispatch/mcp-server.cjsView on unpkgSource passes code obtained from a remote response into a dynamic execution sink.
dist/cli.cjsView on unpkg · L430Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.cjsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/cli.cjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/cli.cjsView on unpkg · L430Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.cjsView on unpkg · L430Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.cjsView on unpkgPackage source references weak cryptographic algorithms.
dist/peer-ops/mcp-server.cjsView on unpkg · L1227Package ships non-JavaScript build or shell helper files.
dist/deploy-kit/scripts/verify.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/deploy-kit/scripts/publish.spec.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/deploy-kit/scripts/publish.shView on unpkgPackage source references child process execution.
dist/dispatch/mcp-server.cjsView on unpkg · L21112Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/dispatch/mcp-server.cjsView on unpkgSource passes code obtained from a remote response into a dynamic execution sink.
dist/cli.cjsView on unpkg · L430Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/cli.cjsView on unpkgManifest-reachable source overwrites another installed package with package-defined remote behavior.
dist/cli.cjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/cli.cjsView on unpkg · L430Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.cjsView on unpkg · L430Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.cjsView on unpkgPackage source references weak cryptographic algorithms.
dist/peer-ops/mcp-server.cjsView on unpkg · L1227Package ships non-JavaScript build or shell helper files.
dist/deploy-kit/scripts/verify.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/deploy-kit/scripts/publish.spec.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/deploy-kit/scripts/publish.shView on unpkg