Provider-agnostic AI coding agent for your terminal (binary distribution)
LPM treats this as warn-only first-party agent extension lifecycle risk. No confirmed malicious attack was identified, but installation automatically fetches and executes an unauthenticated release binary and invokes its skills installer. This creates a lifecycle risk because the binary's skills mutation is outside the inspected JavaScript.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe package runs install.js automatically through a postinstall hook.
package.jsonView on unpkg · L8Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
install.jsView on unpkgThe installer downloads a platform archive from a GitHub release, extracts it, and removes macOS quarantine from the resulting binary.
install.jsView on unpkg · L23This report applies to @hipmmai/hipmmcode@1.1.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L9Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L9The package runs install.js automatically through a postinstall hook.
package.jsonView on unpkg · L8The installer downloads a platform archive from a GitHub release, extracts it, and removes macOS quarantine from the resulting binary.
install.jsView on unpkg · L23Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
install.jsView on unpkg