Running the CLI reads stable identifiers from foreign AI-tool authentication files and transmits their hashes with telemetry. This happens with telemetry enabled by default.
Package source references child process execution.
dist/client/assets/index-BvhnZNuc.jsView on unpkg · L483Source archives sensitive local configuration and publishes encoded chunks through an authenticated package-registry request.
dist/bin.mjsView on unpkg · L13Source appears to send environment or credential material to an external endpoint.
dist/bin.mjsView on unpkg · L13A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bin.mjsView on unpkg · L13This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bin.mjsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bin.mjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bin.mjsView on unpkg · L13Source exposes local file and command tools to a remote model endpoint.
dist/bin.mjsView on unpkg · L21A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/bin.mjsView on unpkg · L13A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/bin.mjsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bin.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/bin.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/NodePtyAdapter-BQAnH2v0.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/BunPtyAdapter-CLDq7yr1.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/client/assets/chunk-4I5QYGJK-CYvb6li-.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/client/assets/chunk-5RXB4S5H-BzE89W2t.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/client/assets/chunk-WRU74C26-C2Rb3ATV.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/client/assets/diagram-Q27KOJAE-Dp_H6G_V.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/client/assets/mdx-host-ykYobBl4.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/client/assets/previewAssetResource-CVDZ-YAw.jsView on unpkgThis report applies to @p4code/cli@0.4.12.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
dist/client/assets/index-BvhnZNuc.jsView on unpkg · L483Source archives sensitive local configuration and publishes encoded chunks through an authenticated package-registry request.
dist/bin.mjsView on unpkg · L13Source appears to send environment or credential material to an external endpoint.
dist/bin.mjsView on unpkg · L13A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/bin.mjsView on unpkg · L13This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/bin.mjsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/bin.mjsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bin.mjsView on unpkg · L13Source exposes local file and command tools to a remote model endpoint.
dist/bin.mjsView on unpkg · L21A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/bin.mjsView on unpkg · L13A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/bin.mjsView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/bin.mjsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/bin.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/NodePtyAdapter-BQAnH2v0.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/BunPtyAdapter-CLDq7yr1.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/client/assets/chunk-4I5QYGJK-CYvb6li-.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/client/assets/chunk-5RXB4S5H-BzE89W2t.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/client/assets/chunk-WRU74C26-C2Rb3ATV.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/client/assets/diagram-Q27KOJAE-Dp_H6G_V.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/client/assets/mdx-host-ykYobBl4.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/client/assets/previewAssetResource-CVDZ-YAw.jsView on unpkg