MagnetAPI.org Codex CLI for ChatGPT-6-Astra, Fable 5.1, Opus 5, Sonnet 5, Daybreak Blue, and GPT-5.6.
LPM flags this version as an AI-agent control-surface risk. An npm postinstall hook can claim unoccupied global codex and claude command names for this package. This is an unconsented mutation of a broad AI-agent command surface.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/codexclaude.jsView on unpkg · L707Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
bin/codexclaude.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/codexclaude.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/codexclaude.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/codexclaude.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-safe-aliases.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/splash.jsView on unpkgThis report applies to @codexapi/codexclaude@2.0.40.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L18Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/splash.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/codexclaude.jsView on unpkg · L707Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
bin/codexclaude.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/codexclaude.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/codexclaude.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/codexclaude.jsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-safe-aliases.jsView on unpkg · L6