Provider-agnostic AI coding agent for your terminal (binary distribution)
LPM treats this as warn-only first-party agent extension lifecycle risk. The postinstall hook downloads and executes a platform binary, then asks it to install default skills. No confirmed credential theft or unrelated control-surface attack was identified in the inspected source.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe package runs install.js automatically through a postinstall hook.
package.jsonView on unpkg · L5Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
install.jsView on unpkgThe installer lets the HIPMMCODE_REPO environment variable select the GitHub release repository.
install.jsView on unpkg · L9This report applies to @hipmmai/hipmmcode@1.1.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L9Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L9The package runs install.js automatically through a postinstall hook.
package.jsonView on unpkg · L5The installer lets the HIPMMCODE_REPO environment variable select the GitHub release repository.
install.jsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
install.jsView on unpkg