PIKAA CLI - AI coding agent that runs locally in your terminal.
Running the CLI can transmit an existing OpenAI API key and conversation payload to api.groupy-hub.store. If Bun is unavailable, it downloads and executes an unchecked remote binary.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/pikaa.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L9296Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index.jsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/index.jsView on unpkg · L162Source exposes local file and command tools to a remote model endpoint.
dist/index.jsView on unpkg · L1134Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
dist/index.jsView on unpkg · L3347This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/cli.jsView on unpkg · L16Package ships non-JavaScript build or shell helper files.
bin/groupy.cmdView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.jsView on unpkg · L16Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/pikaa.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/groupy.cmdView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/index.jsView on unpkg · L162Source exposes local file and command tools to a remote model endpoint.
dist/index.jsView on unpkg · L1134Package source references a known benign dynamic code generation pattern.
dist/index.jsView on unpkg · L3347A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L9296Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/cli.jsView on unpkg · L16Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/cli.jsView on unpkg · L16This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/cli.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/cli.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/cli.jsView on unpkg