Hardware-bound credential vault for the LIFEAI infrastructure stack
Installing the package activates a Windows postinstall hook that creates and starts a privileged, hidden logon persistence task. The task perpetually relaunches the package daemon and the hook can silently install additional system software.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage contains a critical-looking secret pattern.
.clauth-skill/references/keys-guide.mdView on unpkg · L94GitHub personal access token in .clauth-skill/references/keys-guide.md
.clauth-skill/references/keys-guide.mdView on unpkg · L94Package source references child process execution.
cli/watchdog-registry.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/fingerprint.jsView on unpkgPackage source executes code through a VM context API.
cli/supervisor-ui.test.jsView on unpkg · L143Source appears to send environment or credential material to an external endpoint.
cli/commands/serve.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
cli/commands/serve.jsView on unpkg · L6A single source file combines environment access, network access, and code or shell execution; review context before blocking.
cli/http/components/system-component.jsView on unpkg · L147Source file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/http/components/system-component.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
cli/commands/install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/install.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/bootstrap.cjsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bootstrap.cjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
cli/dashboard/dashboard.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/agent-pool.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/doctor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/http/components/tunnel-component.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/mcp/providers/clauth-core-provider.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/studio-debug.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/npm.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/watchdog.jsView on unpkgGitHub personal access token in cli/commands/scrub.test.js
cli/commands/scrub.test.jsView on unpkg · L18This report applies to @lifeaitools/clauth@2.15.16.
See version security history for other recorded verdicts.
Evidence last updated: .
A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
cli/commands/serve.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches persistence behavior.
cli/commands/serve.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/serve.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
cli/commands/serve.jsView on unpkg · L6Package source references weak cryptographic algorithms.
cli/commands/serve.jsView on unpkg · L6Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L16Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L16A single source file combines environment access, network access, and code or shell execution; review context before blocking.
cli/http/components/system-component.jsView on unpkg · L147Source file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/http/components/system-component.jsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
cli/commands/install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/install.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/bootstrap.cjsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bootstrap.cjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
cli/dashboard/dashboard.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/agent-pool.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/doctor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/http/components/tunnel-component.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/mcp/providers/clauth-core-provider.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/studio-debug.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/npm.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/watchdog.jsView on unpkgGitHub personal access token in cli/commands/scrub.test.js
cli/commands/scrub.test.jsView on unpkg · L18Package contains a critical-looking secret pattern.
.clauth-skill/references/keys-guide.mdView on unpkg · L94GitHub personal access token in .clauth-skill/references/keys-guide.md
.clauth-skill/references/keys-guide.mdView on unpkg · L94Package source references child process execution.
cli/watchdog-registry.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/fingerprint.jsView on unpkgPackage source executes code through a VM context API.
cli/supervisor-ui.test.jsView on unpkg · L143Source writes installer persistence such as shell profile or service configuration.
cli/commands/serve.jsView on unpkg · L6Package source references weak cryptographic algorithms.
cli/commands/serve.jsView on unpkg · L6Source appears to send environment or credential material to an external endpoint.
cli/commands/serve.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
cli/commands/serve.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
cli/commands/serve.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches persistence behavior.
cli/commands/serve.jsView on unpkg · L6Source file is highly similar to a previously finalized malicious package; route for source-aware review.
cli/commands/serve.jsView on unpkg