Lightweight multi-agent TUI and stable cross-provider collaboration layer for Codex, Claude, Gemini, Grok, Kimi, and other CLI agents.
Inspected sources are a first-party npm wrapper that vendors the matching GitHub release into the package tree and bootstraps a managed runtime there. No credential theft, foreign agent-control writes, nested self-install chain, or obfuscated dropper remains in this package.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
bin/ask.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ccb-npm-install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/ccb-npm-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ccb-npm-runner.jsView on unpkgThis report applies to @seemseam/ccb@8.6.18.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L54Package source references dynamic require/import behavior.
bin/ask.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ccb-npm-install.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/ccb-npm-install.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/ccb-npm-runner.jsView on unpkg