costrict
LPM treats this as warn-only first-party agent extension lifecycle risk. npm or bun install runs postinstall, which registers this product's Chrome MCP helper and deletes selected CosKnow command files under the current and legacy config directories. That is first-party agent-extension setup plus legacy cleanup, not a shown secret-theft or remote-payload chain. Scanner malware-fingerprint hits track this Claude Code fork family rather than a hidden installer implant in this tarball.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/postinstall.cjsView on unpkg · L15Install-named source file stages remote content through filesystem writes and execution.
scripts/postinstall.cjsView on unpkg · L15Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.cjsView on unpkgRuntime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/setup-chrome-mcp.mjsView on unpkgPackage ships native binary artifacts.
dist/vendor/audio-capture/x64-darwin/audio-capture.nodeView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/cli.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli-node.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/rawDump/batchWorker.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/services/rawDump/batchWorker.jsView on unpkgThis report applies to @costrict/csc@4.2.31.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L77Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L77Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
scripts/setup-chrome-mcp.mjsView on unpkgPackage ships native binary artifacts.
dist/vendor/audio-capture/x64-darwin/audio-capture.nodeView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/cli.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli-node.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/services/rawDump/batchWorker.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/services/rawDump/batchWorker.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/postinstall.cjsView on unpkg · L15Install-named source file stages remote content through filesystem writes and execution.
scripts/postinstall.cjsView on unpkg · L15Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.cjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.cjsView on unpkg