Waterbrother: bring-your-own-model coding CLI with local tools, sessions, operator modes, and approval controls
The package can persist a login-time listener and expose a remotely reachable terminal workflow. These capabilities require explicit CLI commands; no install-time trigger was found.
Package source references child process execution.
vendor/node-pty/lib/windowsPtyAgent.jsView on unpkg · L11Source file is highly similar to a previously finalized malicious package; route for source-aware review.
vendor/node-pty/lib/windowsPtyAgent.jsView on unpkgPackage source references dynamic require/import behavior.
vendor/node-pty/lib/windowsPtyAgent.jsView on unpkg · L8Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools.jsView on unpkgPackage source references weak cryptographic algorithms.
src/codebase-index.jsView on unpkg · L3A manifest entrypoint or package-local install chain reaches persistence behavior.
src/listen-agent.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/listen-agent.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/local-model-runtime.jsView on unpkg · L4Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/cli.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/cli.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/tsnet-join.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tsnet-join.jsView on unpkgPackage ships native binary artifacts.
vendor/node-pty/prebuilds/win32-arm64/pty.nodeView on unpkgPackage ships non-JavaScript build or shell helper files.
src/terminal-shell-hooks.zshView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/acp-proxy.js#virtual:string-array:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/voice.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/game-mcp.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/experiment.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/game-pipeline.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/product.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/terminal-notifications.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
vendor/node-pty/lib/unixTerminal.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/acp-proxy.jsView on unpkgThis report applies to @tritard/waterbrother@0.17.11.
See version security history for other recorded verdicts.
Evidence last updated: .
Source writes installer persistence such as shell profile or service configuration.
src/listen-agent.jsView on unpkg · L3Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
src/cli.jsView on unpkgPackage source references dynamic require/import behavior.
vendor/node-pty/lib/windowsPtyAgent.jsView on unpkg · L8Package source references child process execution.
vendor/node-pty/lib/windowsPtyAgent.jsView on unpkg · L11Source file is highly similar to a previously finalized malicious package; route for source-aware review.
vendor/node-pty/lib/windowsPtyAgent.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/cli.jsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/cli.jsView on unpkg · L1Package ships native binary artifacts.
vendor/node-pty/prebuilds/win32-arm64/pty.nodeView on unpkgPackage ships non-JavaScript build or shell helper files.
src/terminal-shell-hooks.zshView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/acp-proxy.js#virtual:string-array:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/voice.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/game-mcp.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/experiment.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/game-pipeline.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/product.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/terminal-notifications.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
vendor/node-pty/lib/unixTerminal.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/acp-proxy.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools.jsView on unpkgPackage source references weak cryptographic algorithms.
src/codebase-index.jsView on unpkg · L3Source writes installer persistence such as shell profile or service configuration.
src/listen-agent.jsView on unpkg · L3A manifest entrypoint or package-local install chain reaches persistence behavior.
src/listen-agent.jsView on unpkg · L3Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/listen-agent.jsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/local-model-runtime.jsView on unpkg · L4Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
src/cli.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/tsnet-join.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tsnet-join.jsView on unpkg