Bring Grok into your terminal
Installing this typosquatting package automatically installs an attacker-controlled platform binary into the Grok CLI home and changes its configuration. Its launcher claims the official @xai-official/grok identity and runs that binary.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThe manifest uses an automatic postinstall hook despite presenting a different package identity from the official Grok CLI.
package.jsonView on unpkg · L1The manifest uses an automatic postinstall hook despite presenting a different package identity from the official Grok CLI.
package.jsonView on unpkg · L21Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/postinstall.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/grok-bootstrap.jsView on unpkgThe manifest uses an automatic postinstall hook despite presenting a different package identity from the official Grok CLI.
package.jsonView on unpkg · L1Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L22Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L22The manifest uses an automatic postinstall hook despite presenting a different package identity from the official Grok CLI.
package.jsonView on unpkg · L21A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/postinstall.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/grok-bootstrap.jsView on unpkg