Flagged as AI-agent capability risk
Allowed by default with warning: agent-facing configuration or capability changes need review before use.
registry /
@rcdevgames/sembilan-router / 0.5.35-rc.8
@rcdevgames/sembilan-router@0.5.35-rc.8 Sembilan Router CLI - Start and manage Sembilan Router server
AI Security Reviewscanned 16h ago · by lpm-firewall-ai Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Static reason
One or more suspicious static signals were detected.; previous stored version diff introduced dangerous source
Trigger
npm installation for runtime provisioning; user runs the CLI and enables/configures MITM or CLI-tool setup.
Impact
Can intercept and reroute supported AI-client traffic and alter their local configuration, with substantial credential/privacy risk if enabled.
Mechanism
runtime npm installation, local TLS interception, and user-invoked AI-client configuration
Rationale
The source contains real interception and AI-client configuration capabilities, but they are package-aligned and no concrete unconsented AI-control mutation, harvesting, or exfiltration chain was found. Warn for the dangerous capability rather than block as malicious.
Evidence
package.json hooks/postinstall.js hooks/sqliteRuntime.js src/cli/menus/cliTools.js src/cli/tray/autostart.js app/src/mitm/server.js hooks/trayRuntime.js ~/.sembilan-router/runtime
Network endpoints8
registry.npmjs.org /daily-cloudcode-pa.googleapis.com
cloudcode-pa.googleapis.com
api.individual.githubcopilot.com
runtime.us-east-1.kiro.dev
q.us-east-1.amazonaws.com
codewhisperer.us-east-1.amazonaws.com
api2.cursor.sh
Decision evidencepublic snapshot AI called this Suspicious at 91.0% confidence as Dangerous Capability with medium false-positive risk.
Evidence for warning
package.json runs hooks/postinstall.js during install. hooks/postinstall.js installs native/runtime packages under ~/.sembilan-router/runtime. app/src/mitm/server.js implements a TLS MITM proxy and hosts-file DNS redirection. app/src/mitm/server.js targets Codex/Copilot/Kiro/Cursor service hosts. src/cli/menus/cliTools.js exposes user-selected setup for Codex and OpenClaw settings. src/cli/tray/autostart.js can create user autostart entries after tray interaction. Evidence against
Postinstall only provisions package-owned runtime dependencies; no AI-agent configuration is changed there. README.md describes the package as a local AI-routing gateway. CLI-tool and autostart mutations are exposed through explicit interactive menu actions. Inspected code shows no credential harvesting or unrelated exfiltration endpoint. Behavioral surface
Source ChildProcess Crypto DynamicRequire EnvironmentVars Filesystem NativeBindings
Source & flagged code16 flagged · loading source • scripts.postinstall = node hooks/postinstall.js
High Install Time Lifecycle Scripts
Package defines install-time lifecycle scripts.
package.json View on unpkg • scripts.postinstall = node hooks/postinstall.js
Medium Ambiguous Install Lifecycle Script
Install-time lifecycle script is not statically allowlisted and needs review.
package.json View on unpkg app/.next-cli-build/server/chunks/4306.js View file 1 patternName = private_key_rsa
severity = critical
line = 1
matchedText = "use str...}}};
Critical Critical Secret
Package contains a critical-looking secret pattern.
app/.next-cli-build/server/chunks/4306.js View on unpkg · L1 Findings4 Critical 8 High 7 Medium 6 Low
Critical Critical Secret app/.next-cli-build/server/chunks/4306.js
Critical Previous Version Dangerous Delta cli.js
Critical Secret Pattern app/.next-cli-build/server/chunks/4306.js
Critical Secret Pattern app/.next-cli-build/server/chunks/8971.js
High Install Time Lifecycle Scripts package.json
High Child Process app/src/mitm/server.js
High Shell cli.js
High Same File Env Network Execution app/src/mitm/server.js
High Command Output Exfiltration app/src/mitm/server.js
High Cross File Remote Execution Context cli.js
High Runtime Package Install app/src/lib/updater/updater.js
LPM CLI
Network
Shell
Supply chain HighEntropyStrings Minified Obfuscated UrlStrings
Manifest No manifest risk signals triggered.
scanned 35 file(s), 557 KB of source, external domains: 127.0.0.1, api.anthropic.com, api.example.com, registry.npmjs.org, www.apple.com
1 patternName = private_key_rsa
severity = critical
line = 1
matchedText = "use str...}}};
Critical Secret Pattern
RSA private key in app/.next-cli-build/server/chunks/4306.js
app/.next-cli-build/server/chunks/4306.js View on unpkg · L1 32 `)}catch{}}var od=(()=>{let e=new Uint32Array(256);for(let t=0;t<256;t++){let a=t;for(let r=0;r<8;r++)a=a&1?3988292384^a>>>1:a>>>1;e[t]=a}return e})();function Po(e){let t=42949672...
L33: `);t.push({role:"tool",tool_call_id:n.toolUseId||"",content:s})}let r=(e.content||"").trim();return(r||a.length===0)&&t.push({role:"user",content:r}),t}function fd(e){let t=e.toolU...
L34: $proc = Start-Process powershell -ArgumentList @(
High Child Process
Package source references child process execution.
app/src/mitm/server.js View on unpkg · L32 24 Private-MAC: `+B.digest().toHex()+`\r
L25: `,s};ma.publicKeyToOpenSSH=function(e,t){var a="ssh-rsa";t=t||"";var r=Ce.util.createBuffer();return vr(r,a),Et(r,e.e),Et(r,e.n),a+" "+Ce.util.encode64(r.bytes())+" "+t};ma.private...
L26: `);u=c.pop()||"";for(let g of c){let v=g.trim();if(!v||!v.startsWith("data:"))continue;let y=v.slice(5).trim();if(y!=="[DONE]"){process.env.DEBUG_MITM&&Ea(`[SSE in] ${y.slice(0,200...
...
L32: `)}catch{}}var od=(()=>{let e=new Uint32Array(256);for(let t=0;t<256;t++){let a=t;for(let r=0;r<8;r++)a=a&1?3988292384^a>>>1:a>>>1;e[t]=a}return e})();function Po(e){let t=42949672...
L33: `);t.push({role:"tool",tool_call_id:n.toolUseId||"",content:s})}let r=(e.content||"").trim();return(r||a.length===0)&&t.push({role:"user",content:r}),t}function fd(e){let t=e.toolU.
High Same File Env Network Execution
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
app/src/mitm/server.js View on unpkg · L24 24 Private-MAC: `+B.digest().toHex()+`\r
L25: `,s};ma.publicKeyToOpenSSH=function(e,t){var a="ssh-rsa";t=t||"";var r=Ce.util.createBuffer();return vr(r,a),Et(r,e.e),Et(r,e.n),a+" "+Ce.util.encode64(r.bytes())+" "+t};ma.private...
L26: `);u=c.pop()||"";for(let g of c){let v=g.trim();if(!v||!v.startsWith("data:"))continue;let y=v.slice(5).trim();if(y!=="[DONE]"){process.env.DEBUG_MITM&&Ea(`[SSE in] ${y.slice(0,200...
...
L32: `)}catch{}}var od=(()=>{let e=new Uint32Array(256);for(let t=0;t<256;t++){let a=t;for(let r=0;r<8;r++)a=a&1?3988292384^a>>>1:a>>>1;e[t]=a}return e})();function Po(e){let t=42949672...
L33: `);t.push({role:"tool",tool_call_id:n.toolUseId||"",content:s})}let r=(e.content||"").trim();return(r||a.length===0)&&t.push({role:"user",content:r}),t}function fd(e){let t=e.toolU.
• matchType = previous_version_dangerous_delta
matchedPackage = @rcdevgames/sembilan-router@0.5.35-rc.7
matchedIdentity = npm:[redacted]:0.5.35-rc.7
similarity = 0.886
summary = stored previous version shares package body but lacks this dangerous source file
Critical Previous Version Dangerous Delta
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
cli.js View on unpkg 212 if (process.platform === "win32") {
L213: const psCmd = `powershell -NonInteractive -WindowStyle Hidden -Command "Get-WmiObject Win32_Process -Filter 'Name=\\"cloudflared.exe\\"' | Select-Object ProcessId,CommandLine | Con...
L214: const output = execSync(psCmd, { encoding: "utf8", windowsHide: true, timeout: 5000 });
2 Cross-file remote execution chain: cli.js spawns app/src/mitm/server.js; helper contains network access plus dynamic code execution.
L2:
L3: const { spawn, exec, execSync } = require("child_process");
L4: const path = require("path");
L5: const fs = require("fs");
L6: const https = require("https");
L7: const net = require("net");
...
L36: start() {
L37: if (process.stdout.isTTY) {
L38: process.stdout.write(`\r${frames[0]} ${currentText}`);
L39: interval = setInterval(() => {
...
L64:
L65: const pkg = require("./package.json");
High Cross File Remote Execution Context
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.js 1 const path = require('path')
L2:
Medium Dynamic Require
Package source references dynamic require/import behavior.
app/server.js View on unpkg · L1 3 const os = require("os");
L4: const { execSync } = require("child_process");
L5:
...
L36: }
L37: const computed = path.resolve(__dirname, "..", "..", "..", "cli.js");
L38: if (fs.existsSync(computed)) return computed;
...
L47: function enableAutoStart(cliPath) {
L48: const platform = process.platform;
L49:
L50: if (!["darwin", "win32", "linux"].includes(platform)) return false;
L51: if (platform === "linux" && !process.env.DISPLAY) return false;
L52:
Medium Install Persistence
Source writes installer persistence such as shell profile or service configuration.
src/cli/tray/autostart.js View on unpkg · L3 1 // Standalone detached updater process.
L2: // Spawns `npm i -g <pkg>@latest`, exposes progress via tiny HTTP server.
L3: // Survives after parent Next server exits (detached + unref by spawner).
L4:
L5: const { spawn } = require("child_process");
L6: const http = require("http");
High Runtime Package Install
Package source invokes a package manager install command at runtime.
app/src/lib/updater/updater.js View on unpkg · L1 • path = src/cli/tray/tray.ps1
kind = build_helper
sizeBytes = 4009
magicHex = [redacted]
Medium Ships Build Helper
Package ships non-JavaScript build or shell helper files.
src/cli/tray/tray.ps1 View on unpkg app/.next-cli-build/static/media/material-symbols-outlined.ec1fa111.woff2 View file • path = app/.next-cli-build/static/media/material-symbols-outlined.ec1fa111.woff2
kind = high_entropy_blob
sizeBytes = 3962536
magicHex = [redacted]
High Ships High Entropy Blob
Package ships high-entropy non-source blobs.
app/.next-cli-build/static/media/material-symbols-outlined.ec1fa111.woff2 View on unpkg app/.next-cli-build/server/chunks/8971.js View file 1 patternName = private_key_rsa
severity = critical
line = 1
matchedText = "use str...}}};
Critical Secret Pattern
RSA private key in app/.next-cli-build/server/chunks/8971.js
app/.next-cli-build/server/chunks/8971.js View on unpkg · L1 High
Ships High Entropy Blob
app/.next-cli-build/static/media/material-symbols-outlined.ec1fa111.woff2
Medium Ambiguous Install Lifecycle Script package.json
Medium Dynamic Require app/server.js
Medium Install Persistence src/cli/tray/autostart.js
Medium Ships Build Helper src/cli/tray/tray.ps1
Medium Structural Risk Force Deep Review
Low Non Install Lifecycle Scripts
Install lifecycle
postinstall prepublishOnly
Behavioral surface ChildProcess Crypto DynamicRequire EnvironmentVars Filesystem NativeBindings Network Shell HighEntropyStrings Minified Obfuscated UrlStrings Manifest: clean
High Command Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
app/src/mitm/server.js View on unpkg · L24
@rcdevgames/sembilan-router: Suspicious npm security report | LPM Firewall
Source & flagged code16 flagged Lines 5-45 json
6 "sembilan-router" : "./cli.js"
"registry"
:
"https://registry.npmjs.org/"
21 "dev" : "nodemon -I --watch cli.js --watch src --watch hooks --ext js,json cli.js" ,
22 "build" : "node scripts/build-cli.js" ,
23 "pack:cli" : "npm run build && npm pack --pack-destination ../.." ,
24 "publish:cli" : "npm run build && npm publish" ,
25 "postinstall" : "node hooks/postinstall.js" ,
High Install Time Lifecycle Scripts
Package defines install-time lifecycle scripts.
package.json View on unpkg · L25 Medium Ambiguous Install Lifecycle Script
Install-time lifecycle script is not statically allowlisted and needs review.
package.json View on unpkg · L25 26 "prepublishOnly" : "npm run build"
29 "node-machine-id" : "^1.1.12"
31 "comment_sqlite" : "sql.js + better-sqlite3 are NOT bundled here. They are installed into ~/.sembilan-router/runtime/node_modules by hooks/postinstall.js (and re-checked at runtime by cli.js). This avoids Windows EBUSY errors when updating the global CLI, since native .node files no longer live under the locked install dir." ,
32 "comment_systray" : "systray2 is NOT bundled here. It is lazy-installed into ~/.sembilan-router/runtime/node_modules by hooks/postinstall.js on macOS/Linux only. Windows uses PowerShell NotifyIcon (zero binary). This avoids shipping unsigned Go binaries that trigger antivirus false positives (Kaspersky). We use the systray2 fork because the legacy systray@1.0.5 ships a 2017 x86_64 binary that fails on modern macOS dyld." ,
45 "esbuild" : "^0.25.12" ,
app/.next-cli-build/server/chunks/4306.js View file Lines 1-1 javascript
1 "use strict" ; exports .id = 4306 , exports .ids = [ 4306 ], exports .modules = { 37221 :( a , b , c ) => { let
Lines 4-52 javascript
4 ${c} `;qt.writeFileSync(n,v)}catch{}},file:n}}Xn.exports={log:wu,err:Ru,dumpRequest:Uu,createResponseDumper:Pu,clearDumpDir:Lu}});var Y=F((oh,Jn)=>{Jn.exports={options:{usePureJavaScript:!1}}});var ti=F((uh,ei)=>{var wa={};ei.exports=wa;var Zn={};wa.encode=function(e,t,a){if(typeof t!="string")throw new TypeError('"alphabet" must be a string.');if(a!==void 0&&typeof a!="number")throw new TypeError('"maxline" must be a number.');var r="";if(!(e instanceof Uint8Array))r=Ou(e,t);else{var n=0,s=t.length,i=t.charAt(0),o=[0];for(n=0;n<e.length;++n){for(var u=0,l=e[n];u<o.length;++u)l+=o[u]<<8,o[u]=l% ...
5 ` )} return r};wa. decode =function ( e , t ){ if ( typeof e != "string" ) throw
Lines 192-232 javascript
192 process. kill (pid, "SIGKILL" );
195 try { fs. unlinkSync (pidFile); } catch { }
Lines 1-21 javascript
1 const path = require ( 'path' )
2
Medium Dynamic Require
Package source references dynamic require/import behavior.
app/server.js View on unpkg · L1 3 const dir = path. join (__dirname)
Lines 1-23 javascript
1 const fs = require ( "fs" );
2 const path = require ( "path" );
1 // Standalone detached updater process.
L2: // Spawns `npm i -g <pkg>@latest`, exposes progress via tiny HTTP server.
L3: // Survives after parent Next server exits (detached + unref by spawner).
L4:
L5: const { spawn } = require("child_process");
L6: const http = require("http");
High Runtime Package Install
Package source invokes a package manager install command at runtime.
app/src/lib/updater/updater.js View on unpkg · L1 • path = src/cli/tray/tray.ps1
kind = build_helper
sizeBytes = 4009
magicHex = [redacted]
Medium Ships Build Helper
Package ships non-JavaScript build or shell helper files.
src/cli/tray/tray.ps1 View on unpkg app/.next-cli-build/static/media/material-symbols-outlined.ec1fa111.woff2 View file • path = app/.next-cli-build/static/media/material-symbols-outlined.ec1fa111.woff2
kind = high_entropy_blob
sizeBytes = 3962536
magicHex = [redacted]
High Ships High Entropy Blob
Package ships high-entropy non-source blobs.
app/.next-cli-build/static/media/material-symbols-outlined.ec1fa111.woff2 View on unpkg app/.next-cli-build/server/chunks/8971.js View file 1 patternName = private_key_rsa
severity = critical
line = 1
matchedText = "use str...}}};
Critical Secret Pattern
RSA private key in app/.next-cli-build/server/chunks/8971.js
app/.next-cli-build/server/chunks/8971.js View on unpkg · L1 d;c.
d
(b,{
RD
:()
=>
p});
var
e
=
c
(
99129
),f
=
c
(
89419
),g
=
c
(
19035
);
function
h
(
a
){
return
(
0
,g.Gv)(a)}
class
i
{
#a
;
#b
=new
WeakMap;
constructor
(
a
){
if
(
!function
(
a
){
return
a
&&
"object"
==typeof
a
&&
Array.
isArray
(a.keys)
&&
a.keys.
every
(h)}(a))
throw
new
e.
Dm
(
"JSON Web Key Set malformed"
);
this
.#a
=
structuredClone
(a)}jwks(){return this.#a}async getKey(a,b){let{alg:c,kid:d}={...a,...b?.header},f=function(a){switch("string"==typeof a&&a.slice(0,2)){case"RS":case"PS":return"RSA";case"ES":return"EC";case"Ed":return"OKP";case"ML":return"AKP"; ...
Critical Critical Secret
Package contains a critical-looking secret pattern.
app/.next-cli-build/server/chunks/4306.js View on unpkg · L1 Long lines were clipped for display.
1 patternName = private_key_rsa
severity = critical
line = 1
matchedText = "use str...}}};
Critical Secret Pattern
RSA private key in app/.next-cli-build/server/chunks/4306.js
app/.next-cli-build/server/chunks/4306.js View on unpkg · L1
new
TypeError
(
'"input" must be a string.'
);
if
(
typeof
t
!=
"string"
)
throw
new
TypeError
(
'"alphabet" must be a string.'
);
var
a
=
Zn[t];
if
(
!
a){a
=
Zn[t]
=
[];
for
(
var
r
=
0
;r
<
t.
length
;
++
r)a[t.
charCodeAt
(r)]
=
r}e
=
e.
replace
(
/
\s
/
g
,
""
);
for
(
var
n
=
t.
length
,s
=
t.
charAt
(
0
),i
=
[
0
],r
=
0
;r
<
e.
length
;r
++
){
var
o
=
a[e.
charCodeAt
(r)];
if
(o
===void
0
)
return
;
for
(
var
u
=
0
,l
=
o;u
<
i.
length
;
++
u)l
+=
i[u]
*
n,i[u]
=
l
&
255
,l
>>=
8
;
for
(;l
>
0
;)i.
push
(l
&
255
),l
>>=
8
}
for
(
var
f
=
0
;e[f]
===
s
&&
f
<
e.
length
-
1
;
++
f)i.
push
(
0
);
return
typeof
Buffer<
"u"
?
Buffer
.
from
(
i
.
reverse
())
:
new
Uint8Array
(
i
.
reverse
() ...
6 `,a=a.substr(t));return r+=a,r};E.decode64=function(e){e=e.replace(/[^A-Za-z0-9 \+\/\= ]/g,"");for(var t="",a,r,n,s,i=0;i<e.length;)a=Nt[e.charCodeAt(i++)-43],r=Nt[e.charCodeAt(i++)-43],n=Nt[e.charCodeAt(i++)-43],s=Nt[e.charCodeAt(i++)-43],t+=String.fromCharCode(a<<2|r>>4),n!==64&&(t+=String.fromCharCode((r&15)<<4|n>>2),s!==64&&(t+=String.fromCharCode((n&3)<<6|s)));return t};E.encodeUtf8=function(e){return unescape(encodeURIComponent(e))};E.decodeUtf8=function(e){return decodeURIComponent(escape(e))};E.binary={raw:{},hex:{},base64:{},base58:{},baseN:{encode:ai.encode,decode:ai.decode}};E.binary. ...
7 ` , a = a . substr ( t )); return r += a , r }; E . binary . base64 . decode = function ( e , t , a ){ var r
8 `);for(var n="",s=0;s<t*a;++s)n+=" ";switch(r+=n+"Tag: ",e.tagClass){case U.Class.UNIVERSAL:r+="Universal:";break;case U.Class.APPLICATION:r+="Application:";break;case U.Class.CONTEXT_SPECIFIC:r+="Context-Specific:";break;case U.Class.PRIVATE:r+="Private:";break}if(e.tagClass===U.Class.UNIVERSAL)switch(r+=e.type,e.type){case U.Type.NONE:r+=" (None)";break;case U.Type.BOOLEAN:r+=" (Boolean)";break;case U.Type.INTEGER:r+=" (Integer)";break;case U.Type.BITSTRING:r+=" (Bit string)";break;case U.Type.OCTETSTRING:r+=" (Octet string)";break;case U.Type.NULL:r+=" (Null)";break;case U.Type.OID:r+=" (Ob ...
9 ` , r += n + "Constructed: " + e . constructed + `
10 ` , e . composed ){ for ( var i = 0 , o = "" , s = 0 ; s <e.value.length;++ s )e.value[s]!==void 0&&( i + = 1 , o + = U .
11 `, r ; if (e.procType&&( r = {name: "Proc-Type" ,values:[ String (e.procType.version),e.procType.type]}, a + = Wr (r)), e . contentDomain && ( r = {name: "Content-Domain" ,values:[e.contentDomain]}, a + = Wr (r)), e . dekInfo
12 ` ), a += Xr . util . encode64 ( e . body , t . maxline || 64 )+ ` \r
13 ` , a += "-----END " + e . type + `----- \r
14 ` , a }; xi . decode = function ( e ){ for ( var t = [], a = / \s * -----BEGIN ( [A-Z0-9- ] + )----- \r ? \n ? ( [\x21-\x7e\s] +? (?:
15 `;for(var s=0,i=-1,n=0;n<t.length;++n,++s)if(s>65&&i!==-1){var o=t[i];o===","?(++i,t=t.substr(0,i)+` \r
16 `+t.substr(i)):t=t.substr(0,i)+` \r
17 `+o+t.substr(i+1),s=n-i-1,i=-1,++n}else(t[n]===" "||t[n]===" "||t[n]===",")&&(i=n);return t}function Yu(e){return e.replace(/^ \s +/,"")}});var Ir=F((Ch,Ai)=>{var pe=Y();qr();Pa();re();Ai.exports=pe.des=pe.des||{};pe.des.startEncrypting=function(e,t,a,r){var n=Jr({key:e,output:a,decrypt:!1,mode:r||(t===null?"ECB":"CBC")});return n.start(t),n};pe.des.createEncryptionCipher=function(e,t){return Jr({key:e,output:null,decrypt:!1,mode:t})};pe.des.startDecrypting=function(e,t,a,r){var n=Jr({key:e,output:a,decrypt:!0,mode:r||(t===null?"ECB":"CBC")});return n.start(t),n};pe.des.createDecryptionCipher=fu ...
18 ` ;s += "Encryption: " + n + ` \r
20 ` ;var i=Ce.util.createBuffer();vr(i,r),Et(i,e.e),Et(i,e.n);var o=Ce.util.encode64(i.bytes(),64),u=Math.floor(o.length/66)+1;s+= "Public-Lines: " +u+ ` \r
21 ` ,s+=o;var l = Ce.util. createBuffer (); Et (l,e.d), Et ( l ,e.p), Et ( l ,e.q), Et ( l ,e.qInv);var f; if (! t )f=Ce.util. encode64 (l.bytes(), 64 );else{var c=l.length()+ 16 - 1 ;c-=c% 16 ;var g=va(l.bytes());g.truncate(g.length()-c+l.length()),l.putBuffer(g);var v
23 ` ,s+ = f; var S = va ( "putty-private-key-file-mac-key" ,t), A = Ce.util. createBuffer (); vr ( A ,r), vr ( A ,n), vr ( A ,a), A . putInt32 (i. length ()), A
24 Private-MAC: ` + B . digest (). toHex () + ` \r
25 ` ,s};ma. publicKeyToOpenSSH =function ( e , t ){ var a = "ssh-rsa" ;t = t || "" ; var r = Ce.util. createBuffer (); return vr (r,a), Et (r,e.e), Et (r,e.n),a + " " +
26 `);u=c.pop()||"";for(let g of c){let v=g.trim();if(!v||!v.startsWith("data:"))continue;let y=v.slice(5).trim();if(y!=="[DONE]"){process.env.DEBUG_MITM&&Ea(` [ SSE in ] ${y. slice ( 0 , 200 )} `);try{let x=JSON.parse(y),S=a(x,r);if(S!=null){let A=Array.isArray(S)?S:[S];for(let B of A){if(process.env.DEBUG_MITM){let b=B.length||B.byteLength||0;Ea(` [write binary frame] (${b} B ) first 20 B : ${Array. from ( B . slice ( 0 , 20 )). join ( "," )}
27 ` );o = f. pop () || "" ; for ( let c of f){ let g = c. trim (); if ( ! g ||! g. startsWith ( "data:" )) continue ; let v =
29 `),n.end()),s?(t.headersSent||t.writeHead(200,{"Content-Type":"text/event-stream"}),t.end(` data: ${JSON.stringify({ error :{ message :i.message}})}\r
31 `)):(t.headersSent||t.writeHead(500,{"Content-Type":"application/json"}),t.end(JSON.stringify({error:{message:i.message,type:"mitm_error"}})))}}Ro.exports={intercept:Yc}});var Do=F((ip,ko)=>{var{err:$c}=Gt(),{fetchRouter:jc,pipeSSE:Wc}=xa(),Xc={"/chat/completions":"/v1/chat/completions","/v1/messages":"/v1/messages","/responses":"/v1/responses"};function Jc(e){for(let[t,a]of Object.entries(Xc))if(e.includes(t))return a;return"/v1/chat/completions"}async function Zc(e,t,a,r){try{let n=JSON.parse(a.toString());n.model=r;let s=Jc(e.url),i=await jc(n,s,e.headers);await Wc(i,t)}catch(n){$c(` [copilo ...
32 `)}catch{}}var od=(()=>{let e=new Uint32Array(256);for(let t=0;t<256;t++){let a=t;for(let r=0;r<8;r++)a=a&1?3988292384^a>>>1:a>>>1;e[t]=a}return e})();function Po(e){let t=4294967295;for(let a=0;a<e.length;a++)t=t>>>8^od[(t^e[a])&255];return(t^4294967295)>>>0}function ud(e){return{modelId:e||null,toolCallInit:{},hasToolCalls:!1,finishSent:!1,usage:null,inThink:!1,thinkBuf:""}}function Vo(e,t){if(!e)return{thinking:null,text:null};let a=e;t.inThink&&t.thinkBuf&&(a=t.thinkBuf+a,t.thinkBuf="",t.inThink=!1);let r=/<thinking>|<think>/i,n=a.match(r);if(!n)return{thinking:null,text:a};let s=n[0].toLo ...
33 ` );t. push ({role: "tool" ,tool_call_id:n.toolUseId || "" ,content:s})}let r = (e.content || "" ). trim (); return (r || a. length === 0 ) && t. push ({role: "user" ,content:r}),t} function fd ( e
34 $proc = Start - Process powershell - ArgumentList @(
High Same File Env Network Execution
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
app/src/mitm/server.js View on unpkg · L24 High Child Process
Package source references child process execution.
app/src/mitm/server.js View on unpkg · L32 35 '-NoProfile' , '-NonInteractive' , '-ExecutionPolicy' , 'Bypass' ,
36 '-WindowStyle' , 'Hidden' , '-EncodedCommand' , '${t}'
37 ) - Verb RunAs - Wait - PassThru - WindowStyle Hidden;
38 if ($proc.ExitCode - ne 0 ) { throw "Elevated command exited with code $($proc.ExitCode)" }
39 `;return new Promise((r,n)=>{zo(` powershell - NoProfile - NonInteractive - ExecutionPolicy Bypass - Command ${ $o (a)} `,{windowsHide:!0},(s,i,o)=>{if(s){let u=o||s.message;u.includes("canceled by the user")||u.includes("operation was canceled")?n(new Error("User canceled UAC prompt")):n(new Error(u))}else r(i)})})}jo.exports={isAdmin:Yo,runElevatedPowerShell:Ed,quotePs:$o}});var iu=F((hp,nu)=>{var{exec:fp,spawn:Xo,execSync:Or}=require("child_process"),_e=require("fs"),xd=require("path"),cp=require("os"),{log:Sa,err:Sd}=Gt(),{TOOL_HOSTS:Kt}=Go(),{runElevatedPowerShell:Jo,isAdmin:dp}=Wo();function Z ...
40 ` ),s.stdin. end ())})} async function ru ( e ){bt || (eu ?await Vr ( "dscacheutil -flushcache && killall -HUP mDNSResponder" ,e) :await Vr ( "resolvectl flush-caches 2>/dev/null || true" ,e))} function Dn ( e = null ){ try
43 `;Zo(Ze,n,o),await Jo("ipconfig /flushdns | Out-Null")}else{let s=_e.readFileSync(Ze,"utf8").replace(/[ \r\n\s ]+$/g,""),i=r.map(l=>` 127.0 . 0.1 ${l} `).join(`
46 `.replace(/'/g,"' \\ ''");await Vr(` printf '%s' '${u}' | tee ${Ze} > / dev / null `,t),await ru(t)}Sa(` \u{1F310} DNS ${e}: \u2705 added ${r.join( ", " )} `)}catch(n){let s=n.message?.includes("incorrect password")?"Wrong sudo password":` Failed to add DNS entry: ${n.message} `;throw new Error(s)}}async function au(e,t){let a=Kt[e];if(!a)throw new Error(` Unknown tool: ${e} `);let r=a.filter(n=>Dn(n));if(r.length===0){Sa(` \u{1F310} DNS ${e}: already inactive `);return}try{if(bt){let n=_e.readFileSync(Ze,"utf8"),i=n.split(/
47 `).replace(/[ \r\n\s ]+$/g,"")+` \r
48 `;Zo(Ze,n,i),await Jo("ipconfig /flushdns | Out-Null")}else{let o=(_e.readFileSync(Ze,"utf8").split(/ \r ? \n /).filter(u=>!r.some(l=>u.includes(l))).join(`
49 `).replace(/[ \r\n\s ]+$/g,"")+`
50 `).replace(/'/g,"' \\ ''");await Vr(` printf '%s' '${o}' | tee ${Ze} > / dev / null `,t),await ru(t)}Sa(` \u{1F310} DNS ${e}: \u2705 removed ${r.join( ", " )} `)}catch(n){let s=n.message?.includes("incorrect password")?"Wrong sudo password":` Failed to remove DNS entry: ${n.message} `;throw new Error(s)}}async function Bd(e){for(let t of Object.keys(Kt))try{await au(t,e)}catch(a){Sd(` DNS ${t}: failed to remove \u2014 ${a.message} `)}}function bd(){try{if(!_e.existsSync(Ze))return;let e=Object.values(Kt).flat(),t=_e.readFileSync(Ze,"utf8"),a=bt?` \r
52 `,n=t.split(/ \r ? \n /).filter(s=>!e.some(i=>s.includes(i))).join(a).replace(/[ \r\n\s ]+$/g,"")+a;if(n===t)return;if(_e.writeFileSync(Ze,n,"utf8"),bt)try{Or("ipconfig /flushdns",{windowsHide:!0,stdio:"ignore"})}catch{}else if(eu)try{Or("dscacheutil -flushcache && killall -HUP mDNSResponder",{stdio:"ignore"})}catch{}else try{Or("resolvectl flush-caches 2>/dev/null || true",{stdio:"ignore"})}catch{}}catch{}}nu.exports={TOOL_HOSTS:Kt,addDNSEntry:Id,removeDNSEntry:au,removeAllDNSEntries:Bd,removeAllDNSEntriesSync:bd,execWithPassword:Vr,isSudoAvailable:Ta,canRunSudoWithoutPassword:tu,isSudoPasswordRequ ...
Long lines were clipped for display.
24 Private-MAC: `+B.digest().toHex()+`\r
L25: `,s};ma.publicKeyToOpenSSH=function(e,t){var a="ssh-rsa";t=t||"";var r=Ce.util.createBuffer();return vr(r,a),Et(r,e.e),Et(r,e.n),a+" "+Ce.util.encode64(r.bytes())+" "+t};ma.private...
L26: `);u=c.pop()||"";for(let g of c){let v=g.trim();if(!v||!v.startsWith("data:"))continue;let y=v.slice(5).trim();if(y!=="[DONE]"){process.env.DEBUG_MITM&&Ea(`[SSE in] ${y.slice(0,200...
...
L32: `)}catch{}}var od=(()=>{let e=new Uint32Array(256);for(let t=0;t<256;t++){let a=t;for(let r=0;r<8;r++)a=a&1?3988292384^a>>>1:a>>>1;e[t]=a}return e})();function Po(e){let t=42949672...
L33: `);t.push({role:"tool",tool_call_id:n.toolUseId||"",content:s})}let r=(e.content||"").trim();return(r||a.length===0)&&t.push({role:"user",content:r}),t}function fd(e){let t=e.toolU.
High Command Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
app/src/mitm/server.js View on unpkg · L24 198
199 // Kill tunnel processes (cloudflared/tailscale) by their PID files
200 function killTunnelByPidFile () {
201 const tunnelDir = path. join ( getAppDataDir (), "tunnel" );
202 killByPidFile (path. join (tunnelDir, "cloudflared.pid" ));
203 killByPidFile (path. join (tunnelDir, "tailscale.pid" ));
206 // Kill cloudflared whose --url targets this app's port (covers stale PID file case)
207 function killCloudflaredByAppPort ( appPort ) {
208 if ( ! appPort) return [];
209 const portMatchers = [ `localhost:${ appPort }` , `127.0.0.1:${ appPort }` ];
212 if (process.platform === "win32" ) {
213 const psCmd = `powershell -NonInteractive -WindowStyle Hidden -Command "Get-WmiObject Win32_Process -Filter 'Name= \\ "cloudflared.exe \\ "' | Select-Object ProcessId,CommandLine | ConvertTo-Csv -NoTypeInformation"` ;
214 const output = execSync (psCmd, { encoding: "utf8" , windowsHide: true , timeout: 5000 });
215 const lines = output. split ( " \n " ). slice ( 1 ). filter ( l => l. trim ());
216 lines. forEach ( line => {
217 if (portMatchers. some ( m => line. includes (m))) {
218 const match = line. match ( / ^ "( \d + )"/ );
219 if (match && match[ 1 ]) pids. push (match[ 1 ]);
223 const output = execSync ( "ps -eo pid,command 2>/dev/null" , { encoding: "utf8" , timeout: 5000 });
224 output. split ( " \n " ). forEach ( line => {
225 if (line. includes ( "cloudflared" ) && portMatchers. some ( m => line. includes (m))) {
226 const parts = line. trim (). split ( / \s + / );
227 const pid = parts[ 0 ];
228 if (pid && ! isNaN (pid)) pids. push (pid);
• matchType = previous_version_dangerous_delta
matchedPackage = @rcdevgames/sembilan-router@0.5.35-rc.7
matchedIdentity = npm:[redacted]:0.5.35-rc.7
similarity = 0.886
summary = stored previous version shares package body but lacks this dangerous source file
Critical Previous Version Dangerous Delta
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
cli.js View on unpkg 2 Cross-file remote execution chain: cli.js spawns app/src/mitm/server.js; helper contains network access plus dynamic code execution.
L2:
L3: const { spawn, exec, execSync } = require("child_process");
L4: const path = require("path");
L5: const fs = require("fs");
L6: const https = require("https");
L7: const net = require("net");
...
L36: start() {
L37: if (process.stdout.isTTY) {
L38: process.stdout.write(`\r${frames[0]} ${currentText}`);
L39: interval = setInterval(() => {
...
L64:
L65: const pkg = require("./package.json");
High Cross File Remote Execution Context
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
cli.js View on unpkg · L2 5
process.env. NODE_ENV = 'production'
6 process. chdir (__dirname)
8 const currentPort = parseInt (process.env. PORT , 10 ) || 3000
9 const hostname = process.env. HOSTNAME || '0.0.0.0'
11 let keepAliveTimeout = parseInt (process.env. KEEP_ALIVE_TIMEOUT , 10 )
12 const nextConfig = { "env" :{}, "typescript" :{ "ignoreBuildErrors" : false }, "typedRoutes" : false , "distDir" : "./.next-cli-build" , "cleanDistDir" : true , "assetPrefix" : "" , "cacheMaxMemorySize" : 52428800 , "configOrigin"
14 process.env.__NEXT_PRIVATE_STANDALONE_CONFIG = JSON . stringify (nextConfig)
17 const { startServer } = require ( 'next/dist/server/lib/start-server' )
20 Number. isNaN (keepAliveTimeout) ||
21 ! Number. isFinite (keepAliveTimeout) ||
Long lines were clipped for display.
require
(
"os"
);
4 const { execSync } = require ( "child_process" );
5
Medium Install Persistence
Source writes installer persistence such as shell profile or service configuration.
src/cli/tray/autostart.js View on unpkg · L3 6 const APP_NAME = "sembilan-router" ;
7 const APP_LABEL = "com.sembilan-router.autostart" ;
10 * Resolve the absolute path to this package's cli.js.
12 * Order of preference:
13 * 1. Explicit `cliPath` argument — cleanest, used when called from running
14 * cli.js with `__filename`.
15 * 2. `process.argv[1]` if it's our cli.js — true when sembilan-router is currently
16 * running and the tray menu fires this code path.
17 * 3. Compute relative to this file's own location. autostart.js lives at
18 * `<pkg>/src/cli/tray/autostart.js`, so cli.js is three levels up.
19 * This works for any global install layout (nvm, Volta, asdf, Homebrew,
20 * /usr/local, etc.) without depending on `npm bin -g` (removed in npm 9)
21 * or a hardcoded `/usr/local/...` path.
23 * Returns null if no candidate exists — callers should not write an autostart
=
t;
r
||
(
r
=new
Uint8Array
(Math.
ceil
(e.
length
/
4
)
*
3
)),
e
=
e.
replace
(
/
[
^
A-Za-z0-9
\+\/\=
]
/
g
,
""
),
a
=
a
||
0
;
for
(
var
n
,
s
,
i
,
o
,
u
=
0
,
l
=
a;
u
<e.length;)n=Nt[e.
charCodeAt
(
u
++)-43],
s
=
Nt[e.
charCodeAt
(u
++
)
-
43
],
i
=
Nt[e.
charCodeAt
(u
++
)
-
43
],
o
=
Nt[e.
charCodeAt
(u
++
)
-
43
],
r
[l
++
]
=
n
<<
2
|
s
>>
4
,
i
!
==
64
&&(
r
[l
++
]
=
(s
&
15
)
<<
4
|
i
>>
2
,
o
!
==
64
&&(
r
[l
++
]
=
(i
&
3
)
<<
6
|
o));
return
t
?
l
-
a
:
r
.
subarray
(0,
l
)};
E
.
binary
.
base58
.
encode
=
function
(
e
,
t
){
return
E
.
binary
.
baseN
.
encode
(
e
,
ni
,
t
)};
E
.
binary
.
base58
.
decode
=
function
(
e
,
t
){
return
E
.
binary
.
baseN
.
decode
(
e
,
ni
,
t
)};
E
.
text
={
utf8
:
{},
utf16
:
{}};
E
. ...
prettyPrint
(e.value[s],t
+
1
,a),
s
+1<e.value.length&&(
o
+
=
","
));
r
+=
n
+
"Sub values: "
+
i
+
o
}
else
{
if
(
r
+
=
n
+
"Value: "
,e.type===U.Type.OID){
var
u
=
U
.
derToOid
(e.value);r
+=
u,de.pki
&&
de.pki.oids
&&
u
in
de.pki.oids
&&
(r
+=
" ("
+
de.pki.oids[u]
+
") "
)}if(e.type===U.Type.INTEGER)try{r+=U.derToInteger(e.value)}catch{r+="0x"+de.util.bytesToHex(e.value)}else if(e.type===U.Type.BITSTRING){if(e.value.length>1?r+="0x"+de.util.bytesToHex(e.value.slice(1)):r+="(none)",e.value.length>0){var l=e.value.charCodeAt(0);l==1?r+=" (1 unused bit sh ...
&&
(
r
=
{name:
"DEK-Info"
,values:[e.dekInfo.algorithm]},e.dekInfo.parameters&&r.values.push(e.dekInfo.parameters),
a
+=
Wr
(
r
)),
e
.
headers
)
for
(
var
n
=
0
;
n
<e.headers.length;++
n
)a+=
Wr
(e.headers[
n
]);
return
e
.
procType
&&
(
a
+
=
`
\r
\r
?
\n\r
?
\n
))
?
(
[:A-Za-z0-9+
\/
=\s]
+?
)-----END
\1
-----/
g
,
r
=
/(
[\x21-\x7e]
+
):
\s
*
(
[\x21-\x7e\s^:]
+
)/
,
n
=
/
\r
?
\n
/
,
s
;
s
=
a.
exec
(e),!!
s
;){
var
i
=
s[
1
];i
===
"NEW CERTIFICATE REQUEST"
&&
(i
=
"CERTIFICATE REQUEST"
);
var
o
=
{type:i,procType:
null
,contentDomain:
null
,dekInfo:
null
,headers:[],body:Xr.util.
decode64
(s[
3
])};
if
(t.
push
(o),
!!
s[
2
]){
for
(
var
u
=
s[
2
].
split
(n),l
=
0
;s
&&
l
<
u.
length
;){
for
(
var
f
=
u[l].
replace
(
/
\s
+$
/
,
""
),c
=
l
+
1
;c
<
u.
length
;
++
c){
var
g
=
u[c];
if
(
!
/
\s
/
.
test
(g[
0
]))
break
;f
+=
g,l
=
c}
if
(s
=
f.
match
(r),s){
for
(
var
v
=
{name:s[
1
],
...
=
Ce.util.
createBuffer
();v.
putBuffer
(
va
(
"
\0\0\0\0
"
,t)),v.putBuffer(
va
(
"
\0\0\0
"
,
t
));var y
=
Ce.aes.
createEncryptionCipher
(v.
truncate
(
8
),
"CBC"
);y.
start
(Ce.util.
createBuffer
().
fillWithByte
(
0
,
16
)),y.update(l.copy()),y.finish();var x
=
y.output;x.
truncate
(
16
),f
=
Ce.util.
encode64
(x.
bytes
(),
64
)}u
=
Math.
floor
(f.
length
/
66
)
+
1
,s+
=
`
\r
.
putBuffer
(i),
A
.
putInt32
(l.
length
()),
A
.
putBuffer
(l);
var
B
=
Ce.hmac.
create
();return
B
.
start
(
"sha1"
,
S
),
B
.
update
(
A
.
bytes
()),s
+=
`
\r
Ce.util.
encode64
(r.
bytes
())
+
" "
+
t};ma.
privateKeyToOpenSSH
=function
(
e
,
t
){
return
t
?
Ce.pki.
encryptRsaPrivateKey
(e,t,{legacy:
!
0
,algorithm:
"aes128"
})
:
Ce.pki.
privateKeyToPem
(e)};ma.
getPublicKeyFingerprint
=function
(
e
,
t
){t
=
t
||
{};
var
a
=
t.md
||
Ce.md.md5.
create
(),r
=
"ssh-rsa"
,n
=
Ce.util.
createBuffer
();
vr
(n,r),
Et
(n,e.e),
Et
(n,e.n),a.
start
(),a.
update
(n.
getBytes
());
var
s
=
a.
digest
();
if
(t.encoding
===
"hex"
){
var
i
=
s.
toHex
();
return
t.delimiter
?
i.
match
(
/
.
{2}
/
g
).
join
(t.delimiter)
:
i}els
...
`)}t.write(Buffer.from(B))}}}catch{}}}}try{let l=a(null,r);if(l!=null){let f=Array.isArray(l)?l:[l];for(let c of f)t.write(c)}}catch{}t.end()}async function Mc(e,t,a,r){let n={"Content ...
g.
slice
(
5
).
trim
();
if
(v
!==
"[DONE]"
){process.env.
DEBUG_MITM
&&
Ea
(
`[SSE in] ${
v
.
slice
(
0
,
200
)
}`
);
try
{
let
y
=
JSON
.
parse
(v),x
=
a
(y,r);
if
(x
!=
null
){
let
S
=
Array.
isArray
(x)
?
x
:
[x];
for
(
let
A
of
S
){
if
(process.env.
DEBUG_MITM
){
let
B
=
A
.
length
||
A
.byteLength
||
0
;
Ea
(
`[write binary frame] (${
B
}B) first 20B: ${
Array
.
from
(
A
.
slice
(
0
,
20
)).
join
(
","
)
}`
)}t.
write
(Buffer.
from
(
A
))}}}
catch
{}}}}try{let u
=
a
(
null
,r);
if
(u
!=
null
){let l
=
Array.
isArray
(u)
?
u
:
[u];
for
(let f
of
l)t.
write
(f)}}catch{}t.
end
()}wo.exports
=
{fetchRouter:Vc,pipeSSE:Fc,pipe
...
){
let
t
=
e.toolUses
||
[];
return
t.
length
>
0
?
{role:
"assistant"
,content:e.content
||
null
,tool_calls:t.
map
(
a
=>
({id:a.toolUseId
||
`call_${
Date
.
now
()
}`
,type:
"function"
,function:{name:a.name
||
""
,arguments:
ld
(a.input)}}))}
:
{role:
"assistant"
,content:e.content
||
""
}}
function
cd
(
e
){
let
t
=
e.conversationState
||
{},a
=
t.history
||
[],r
=
t.currentMessage,n
=
[];
for
(
let
s
of
a)s.userInputMessage
?
n.
push
(
...
Oo
(s.userInputMessage))
:
s.assistantResponseMessage
&&
n.
...
{
let
t
=
_e.
readFileSync
(Ze,
"utf8"
);
return
e
?
t.
includes
(e)
:
Kt.antigravity.
every
(
a
=>
t.
includes
(a))}
catch
{
return!
1
}}
function
Ad
(){
try
{
let
e
=
_e.
readFileSync
(Ze,
"utf8"
),t
=
{};
for
(
let
[a,r]
of
Object.
entries
(Kt))t[a]
=
r.
every
(
n
=>
e.
includes
(n));
return
t}
catch
{
return
Object.
fromEntries
(Object.
keys
(Kt).
map
(
e
=>
[e,
!
1
]))}}
async
function
Id
(
e
,
t
){
let
a
=
Kt[e];
if
(
!
a)
throw
new
Error
(
`Unknown tool: ${
e
}`
);
let
r
=
a.
filter
(
...
\r
?
\n
/).filter(o=>!r.some(u=>o.includes(u))).join(`
\r
:
"next.config.mjs"
,
"useFileSystemPublicRoutes"
:
true
,
"generateEtags"
:
true
,
"pageExtensions"
:[
"tsx"
,
"ts"
,
"jsx"
,
"js"
],
"poweredByHeader"
:
true
,
"compress"
:
true
,
"images"
:{
"deviceSizes"
:[
640
,
750
,
828
,
1080
,
1200
,
1920
,
2048
,
3840
],
"imageSizes"
:[
32
,
48
,
64
,
96
,
128
,
256
,
384
],
"path"
:
"/_next/image"
,
"loader"
:
"default"
,
"loaderFile"
:
""
,
"domains"
:[],
"disableStaticImages"
:
false
,
"minimumCacheTTL"
:
14400
,
"formats"
:[
"image/webp ..
.