Bring Grok into your terminal
Installing the package extracts a compressed executable from a platform-specific optional dependency into the user's Grok directory. The executable is then launched by the grok command wrapper, but its contents are not available in this package for inspection.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgAn automatic postinstall hook runs package code during npm installation.
package.jsonView on unpkg · L21Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/postinstall.jsView on unpkgThe hook decompresses an opaque platform-package binary into the user's Grok directory.
bin/postinstall.jsView on unpkg · L68Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/grokView on unpkgThe command wrapper executes that extracted binary when the grok command is used.
bin/grokView on unpkg · L140The README directs users to a different npm scope, which is consistent with impersonation risk.
README.mdView on unpkg · L13This report applies to @kingingwang/grok@1.0.12-8d051d60.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L22Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L22An automatic postinstall hook runs package code during npm installation.
package.jsonView on unpkg · L21The hook decompresses an opaque platform-package binary into the user's Grok directory.
bin/postinstall.jsView on unpkg · L68Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/postinstall.jsView on unpkgThe command wrapper executes that extracted binary when the grok command is used.
bin/grokView on unpkg · L140Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/grokView on unpkgThe README directs users to a different npm scope, which is consistent with impersonation risk.
README.mdView on unpkg · L13