PIKAA CLI - AI coding agent that runs locally in your terminal.
On explicit CLI use, the package can download and execute an unchecked remote binary. Its model client also forwards an OpenAI API key to a fixed third-party gateway by default.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/pikaa.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L9296Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index.jsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/index.jsView on unpkg · L162Source exposes local file and command tools to a remote model endpoint.
dist/index.jsView on unpkg · L1134Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/index.jsView on unpkg · L3347This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/cli.jsView on unpkg · L16Package ships non-JavaScript build or shell helper files.
bin/groupy.cmdView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.jsView on unpkg · L16Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/pikaa.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/groupy.cmdView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/index.jsView on unpkg · L162Source exposes local file and command tools to a remote model endpoint.
dist/index.jsView on unpkg · L1134Package source references a known benign dynamic code generation pattern.
dist/index.jsView on unpkg · L3347A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L9296Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/cli.jsView on unpkg · L16Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.jsView on unpkg · L16This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.jsView on unpkg