Hum: a self-improving coding agent for your terminal.
npm installation automatically obtains and executes remote installer code, then installs an external Python core. When the CLI runs, its update mechanism can also start detached remote installers.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/install.mjsView on unpkgPackage source references dynamic require/import behavior.
bin/hum.jsView on unpkg · L8Source appears to collect browser login credentials for exfiltration.
dist/cli.mjsView on unpkg · L317A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli.mjsView on unpkg · L83496This report applies to @metaphi-ai/hum@0.1.84.
See version security history for other recorded verdicts.
Evidence last updated: .
Source exposes local file and command tools to a remote model endpoint.
dist/cli.mjsView on unpkg · L32611Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L9Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L9Source appears to collect browser login credentials for exfiltration.
dist/cli.mjsView on unpkg · L317A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/cli.mjsView on unpkg · L83496Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/install.mjsView on unpkgPackage source references dynamic require/import behavior.
bin/hum.jsView on unpkg · L8Source exposes local file and command tools to a remote model endpoint.
dist/cli.mjsView on unpkg · L32611Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.mjsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.mjsView on unpkg