codex-ultra workbench launcher: prebuilt server + web UI for every platform (cxu starts it all).
No automatic install-time attack was confirmed. On explicit CLI use, the obfuscated launcher can start a bundled platform executable and the library contains broad file, process, and HTTP primitives.
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1Published JavaScript is heavily obfuscated, including a runtime string decoder, which prevents reliable review of its broad file, process, and HTTP capabilities.
dist/index.jsView on unpkg · L1Package contains source files above the normal full-analysis size ceiling.
web-dist/assets/main-4g10184v.jsView on unpkgThis report applies to @codex-ultra/cxu@0.2.7.
See version security history for other recorded verdicts.
Evidence last updated: .
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/index.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1Published JavaScript is heavily obfuscated, including a runtime string decoder, which prevents reliable review of its broad file, process, and HTTP capabilities.
dist/index.jsView on unpkg · L1Package contains source files above the normal full-analysis size ceiling.
web-dist/assets/main-4g10184v.jsView on unpkg