Provider-agnostic AI coding agent for your terminal (binary distribution)
Installing the package downloads a mutable latest-release binary from GitHub, extracts it, and executes it. The source provides no checksum or signature verification.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe postinstall hook automatically runs install.js.
package.jsonView on unpkg · L8Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
install.jsView on unpkgThe installer accepts HIPMMCODE_REPO and fetches a latest-release archive without an integrity check.
install.jsView on unpkg · L9This report applies to @hipmmai/hipmmcode@1.1.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L9Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L9The postinstall hook automatically runs install.js.
package.jsonView on unpkg · L8The installer accepts HIPMMCODE_REPO and fetches a latest-release archive without an integrity check.
install.jsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
install.jsView on unpkg