OneScience AI coding agent for the terminal.
npm postinstall fetches an unauthenticated remote native archive, extracts it into node_modules, and exposes its binary through the package launcher. A network attacker or archive host compromise can stage arbitrary executable content for later user invocation.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L10Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
platform-bootstrap.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L11Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L11Install-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
platform-bootstrap.mjsView on unpkg