Nimbus runtime package for Cloudflare Workers, re-exported publicly through @nimbus-sh/sdk/worker.
The runtime includes a credential-login flow that can execute a command supplied by remote provider metadata. No automatic install-time attack was identified.
Package source references child process execution.
dist/facets/process.js#virtual:normalized:round1View on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/facets/process.js#virtual:normalized:round1View on unpkgSource fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
public/_assets/real-vite-bundle.jsView on unpkg · L200Source passes code obtained from a remote response into a dynamic execution sink.
public/_assets/real-vite-bundle.jsView on unpkgPackage source references shell execution.
public/_assets/real-vite-bundle.jsView on unpkg · L69352Source contains an obfuscated payload loader that reconstructs and executes hidden code.
public/_assets/real-vite-bundle.jsView on unpkg · L22909Source file is highly similar to a previously finalized malicious package; route for source-aware review.
public/_assets/real-vite-bundle.jsView on unpkgPackage source references dynamic code evaluation.
dist/facets/real-vite-fs-shim.js#virtual:normalized:round1View on unpkg · L780Package source references dynamic require/import behavior.
dist/runtime/opencode-facet-runner.js#virtual:normalized:round1View on unpkg · L65A single source file combines environment access, network access, and code or shell execution; review context before blocking.
public/_assets/runtime/git-de3e60c9f3ff006a.jsView on unpkg · L1Package source references weak cryptographic algorithms.
public/_assets/runtime/git-de3e60c9f3ff006a.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/facets/manager.jsView on unpkg · L6Package source invokes a package manager install command at runtime.
scripts/bundle-real-vite.mjsView on unpkg · L377Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bundle-real-vite.mjsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
public/_assets/opencode/1.16.2/index-attach.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bundle-plugin-react.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bundle-npm-cjs.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/facets/real-vite-fs-shim.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
public/_assets/opencode/1.16.2/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/opentui/build-wasm.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
public/_assets/tailwind-play.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/facets/vite-dev-server.jsView on unpkgThis report applies to @nimbus-sh/worker@0.11.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
dist/facets/process.js#virtual:normalized:round1View on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/facets/process.js#virtual:normalized:round1View on unpkgSource fetches a remote non-code asset, decodes its contents, and dynamically executes the decoded payload.
public/_assets/real-vite-bundle.jsView on unpkg · L200Source passes code obtained from a remote response into a dynamic execution sink.
public/_assets/real-vite-bundle.jsView on unpkgPackage source references shell execution.
public/_assets/real-vite-bundle.jsView on unpkg · L69352Source contains an obfuscated payload loader that reconstructs and executes hidden code.
public/_assets/real-vite-bundle.jsView on unpkg · L22909Source file is highly similar to a previously finalized malicious package; route for source-aware review.
public/_assets/real-vite-bundle.jsView on unpkgPackage source references dynamic code evaluation.
dist/facets/real-vite-fs-shim.js#virtual:normalized:round1View on unpkg · L780Package source references dynamic require/import behavior.
dist/runtime/opencode-facet-runner.js#virtual:normalized:round1View on unpkg · L65Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/facets/manager.jsView on unpkg · L6Package source invokes a package manager install command at runtime.
scripts/bundle-real-vite.mjsView on unpkg · L377Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bundle-real-vite.mjsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
public/_assets/opencode/1.16.2/index-attach.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bundle-plugin-react.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/bundle-npm-cjs.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/facets/real-vite-fs-shim.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
public/_assets/opencode/1.16.2/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/opentui/build-wasm.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
public/_assets/tailwind-play.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/facets/vite-dev-server.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
public/_assets/runtime/git-de3e60c9f3ff006a.jsView on unpkg · L1Package source references weak cryptographic algorithms.
public/_assets/runtime/git-de3e60c9f3ff006a.jsView on unpkg · L1