npm postinstall silently fetches and executes a third-party git-ai installer from GitHub, then writes that tool's config in the user home directory. An interactive or npx path can also start the native cubic setup command. The installer body is not in this package, so what the remote script changes cannot be fully verified here.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/cubic.cmdView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
postinstall.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
postinstall.mjsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
postinstall.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cubicView on unpkgThis report applies to @cubic-dev-ai/cli@1.13.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L8Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L9Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L9Package ships non-JavaScript build or shell helper files.
bin/cubic.cmdView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
postinstall.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
postinstall.mjsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
postinstall.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cubicView on unpkg