THE single public author surface for Hilinga plugins: createPlugin, auth guards, the workspace-scoped data surface (makeDataSurface) + migrations + withTenantContext, cross-plugin RPC, and the wire-protocol verify surface. One npm package, no -composite/-
Importing the package loads an opaque obfuscated main bundle whose full behavior cannot be verified. Its CLI can run a selected plugin's server code only after the user explicitly invokes it.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cli.mjsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/index.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/dev/serve.ts#virtual:normalized:round1View on unpkg · L23A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/dev/serve.ts#virtual:normalized:round1View on unpkgPackage ships high-entropy non-source blobs.
shell/_server/assets/app-DHSje8fl.css.gzView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
shell/_build/.vite/manifest.json.gzView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/dev/dev-host.tsView on unpkgThis report applies to @kahitsan/plugin-sdk@0.8.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cli.mjsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/index.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/dev/serve.ts#virtual:normalized:round1View on unpkg · L23A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/dev/serve.ts#virtual:normalized:round1View on unpkgPackage ships high-entropy non-source blobs.
shell/_server/assets/app-DHSje8fl.css.gzView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
shell/_build/.vite/manifest.json.gzView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/dev/dev-host.tsView on unpkg