Synaptic Code is no longer distributed through npm.
Static analysis flagged 18 finding(s) at 97.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package source references child process execution.
dist/NodeServices-Bj0xFD_Q.mjsView on unpkg · L6Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/NodeServices-Bj0xFD_Q.mjsView on unpkg · L6Package source references dynamic require/import behavior.
dist/client/assets/typescript-S0auFSj_.jsView on unpkg · L1Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/client/assets/ComposerPromptEditor-CbBtETqa.jsView on unpkg · L5Package ships WebAssembly modules.
dist/client/assets/ghostty-vt-DdA0Zryv.wasmView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bin.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/bin.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/NodePtyAdapter-D_767uyO.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/BunPtyAdapter-LCaDIzTx.mjsView on unpkgThis report applies to @dmccore/code@0.0.40-synaptic.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
dist/NodeServices-Bj0xFD_Q.mjsView on unpkg · L6Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/NodeServices-Bj0xFD_Q.mjsView on unpkg · L6Package ships WebAssembly modules.
dist/client/assets/ghostty-vt-DdA0Zryv.wasmView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bin.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/bin.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/NodePtyAdapter-D_767uyO.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/BunPtyAdapter-LCaDIzTx.mjsView on unpkgPackage source references dynamic require/import behavior.
dist/client/assets/typescript-S0auFSj_.jsView on unpkg · L1Source contains bidi control or invisible Unicode characters associated with Trojan Source attacks.
dist/client/assets/ComposerPromptEditor-CbBtETqa.jsView on unpkg · L5