THE single public author surface for Hilinga plugins: createPlugin, auth guards, the workspace-scoped data surface (makeDataSurface) + migrations + withTenantContext, cross-plugin RPC, and the wire-protocol verify surface. One npm package, no -composite/-
The main bundle embeds reviewer-directed instructions that attempt to suppress source inspection. This supports a warning, but no executable attack was confirmed.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cli.mjsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/index.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/dev/serve.tsView on unpkg · L42Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/dev/serve.tsView on unpkgPackage ships high-entropy non-source blobs.
shell/_server/assets/app-DBwQ1Y_5.css.brView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
shell/_build/.vite/manifest.json.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/dev/serve.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/dev/sqlite-pool.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/dev/dev-host.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/dev/dev-host.tsView on unpkgThis report applies to @kahitsan/plugin-sdk@0.9.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cli.mjsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/index.jsView on unpkg · L1Package ships high-entropy non-source blobs.
shell/_server/assets/app-DBwQ1Y_5.css.brView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
shell/_build/.vite/manifest.json.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/dev/serve.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/dev/sqlite-pool.tsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/dev/dev-host.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/dev/dev-host.tsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/dev/serve.tsView on unpkg · L42Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/dev/serve.tsView on unpkg