Lightweight multi-agent TUI and stable cross-provider collaboration layer for Codex, Claude, Gemini, Grok, Kimi, and other CLI agents.
The postinstall hook downloads an opaque release archive, verifies it against a checksum fetched from that same location, extracts it, and executes its shell installer. This gives the remote release content code execution during npm installation.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
bin/ask.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ccb-npm-install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/ccb-npm-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ccb-npm-runner.jsView on unpkgThis report applies to @seemseam/ccb@8.6.16.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L54Package source references dynamic require/import behavior.
bin/ask.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ccb-npm-install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/ccb-npm-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ccb-npm-runner.jsView on unpkg