Provider-agnostic AI coding agent for your terminal (binary distribution)
Installation retrieves a mutable external binary and executes it automatically. The package does not pin or verify the archive, so npm installation can run code outside the reviewed snapshot.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgIts postinstall hook downloads a mutable latest-release archive from GitHub without an integrity check.
package.jsonView on unpkg · L8Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
install.jsView on unpkgIts postinstall hook downloads a mutable latest-release archive from GitHub without an integrity check.
install.jsView on unpkg · L22This report applies to @hipmmai/hipmmcode@1.1.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L9Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L9Its postinstall hook downloads a mutable latest-release archive from GitHub without an integrity check.
package.jsonView on unpkg · L8Its postinstall hook downloads a mutable latest-release archive from GitHub without an integrity check.
install.jsView on unpkg · L22Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
install.jsView on unpkg