THE single public author surface for Hilinga plugins: createPlugin, auth guards, the workspace-scoped data surface (makeDataSurface) + migrations + withTenantContext, cross-plugin RPC, and the wire-protocol verify surface. One npm package, no -composite/-
The shipped import bundle is deliberately obfuscated and begins with encoded reviewer-directed text that attempts to stop analysis. No concrete runtime attack behavior was established from the inspected source.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cli.mjsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/index.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/dev/serve.tsView on unpkg · L42Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/dev/serve.tsView on unpkgPackage ships high-entropy non-source blobs.
shell/_server/assets/app-DBwQ1Y_5.css.brView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
shell/_build/.vite/manifest.json.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/dev/serve.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/dev/sqlite-pool.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/dev/dev-host.tsView on unpkgThis report applies to @kahitsan/plugin-sdk@0.10.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cli.mjsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/index.jsView on unpkg · L1Package ships high-entropy non-source blobs.
shell/_server/assets/app-DBwQ1Y_5.css.brView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
shell/_build/.vite/manifest.json.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/dev/serve.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/dev/sqlite-pool.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/dev/dev-host.tsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/dev/serve.tsView on unpkg · L42Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/dev/serve.tsView on unpkg