OpenCode plugin for Paytaca AI - AI inference provider powered by Bitcoin Cash micropayments
LPM treats this as warn-only first-party agent extension lifecycle risk. Automatic installation changes a global CLI entry. When OpenCode loads the plugin, it creates persistent Paytaca files, installs a global skill, starts a local proxy, and registers an enabled MCP server that can access wallet functions.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/paytaca.jsView on unpkgPackage source references dynamic require/import behavior.
bin/paytaca.jsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/proxy.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/proxy.jsView on unpkgPackage source references weak cryptographic algorithms.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bundled/mcp.jsView on unpkg · L22Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bundled/mcp.jsView on unpkgSource combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bundled/proxy.js#virtual:normalized:round1View on unpkg · L199A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bundled/proxy.js#virtual:normalized:round1View on unpkg · L199Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/bundled/proxy.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/bundled/proxy.jsView on unpkg · L16Package source invokes a package manager install command at runtime.
scripts/postinstall.jsView on unpkg · L91Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/wallet.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bundled/proxy.jsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L22Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L22Package source references dynamic require/import behavior.
bin/paytaca.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bundled/proxy.js#virtual:normalized:round1View on unpkg · L199A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/bundled/proxy.js#virtual:normalized:round1View on unpkg · L199Package source invokes a package manager install command at runtime.
scripts/postinstall.jsView on unpkg · L91Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/wallet.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/paytaca.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/proxy.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/proxy.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bundled/mcp.jsView on unpkg · L22Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bundled/mcp.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/bundled/proxy.jsView on unpkg · L16Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/bundled/proxy.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bundled/proxy.jsView on unpkg