Provider-agnostic AI coding agent for your terminal (binary distribution)
Installation retrieves an opaque release archive, extracts it, and invokes code from that archive. The release repository can be changed through an environment variable, so the install-time payload is not fixed by this package snapshot.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe package runs install.js automatically through a postinstall hook.
package.jsonView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
install.jsView on unpkgThe installer permits its release repository to be selected through an environment variable.
install.jsView on unpkg · L9This report applies to @hipmmai/hipmmcode@1.1.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L9Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L9The package runs install.js automatically through a postinstall hook.
package.jsonView on unpkg · L5The installer permits its release repository to be selected through an environment variable.
install.jsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
install.jsView on unpkg