Reverse-engineered Anthropic Claude Code CLI — interactive AI coding assistant in the terminal
LPM treats this as warn-only first-party agent extension lifecycle risk. Install-time scripts register a Chrome MCP bridge and may fetch a ripgrep executable. The fetched executable lacks an in-package integrity check, leaving a supply-chain exposure.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references child process execution.
dist/chunks/protocolHandler-DRDjncTx.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/postinstall.cjsView on unpkg · L23Install-named source file stages remote content through filesystem writes and execution.
scripts/postinstall.cjsView on unpkg · L23Package source references dynamic require/import behavior.
Package source references weak cryptographic algorithms.
dist/chunks/dist-es-fjXft-jH.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/chunks/main-CSZrZE1o.jsView on unpkg · L9Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
Source appears to collect browser login credentials for exfiltration.
dist/chunks/esm-CsGLyWmS.jsView on unpkg · L1Source reaches cloud instance metadata or link-local credential endpoints.
dist/chunks/dist-es-DuAZyxJ02.jsView on unpkg · L3Package ships native binary artifacts.
dist/vendor/audio-capture/x64-darwin/audio-capture.nodeView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/chunks/loadAgentsDir-w4TqBaJZ.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/REPL-nTtiK-bJ.jsView on unpkgSource spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunks/main-CSZrZE1o.jsView on unpkg · L1Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L69Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L69Source reaches cloud instance metadata or link-local credential endpoints.
dist/chunks/dist-es-DuAZyxJ02.jsView on unpkg · L3Package ships native binary artifacts.
dist/vendor/audio-capture/x64-darwin/audio-capture.nodeView on unpkgPackage contains source files above the normal full-analysis size ceiling.
dist/chunks/loadAgentsDir-w4TqBaJZ.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/chunks/REPL-nTtiK-bJ.jsView on unpkgPackage source references child process execution.
dist/chunks/protocolHandler-DRDjncTx.jsView on unpkg · L1Package source references dynamic require/import behavior.
scripts/postinstall.cjsView on unpkg · L22Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/postinstall.cjsView on unpkg · L23Install-named source file stages remote content through filesystem writes and execution.
scripts/postinstall.cjsView on unpkg · L23Package source references weak cryptographic algorithms.
dist/chunks/dist-es-fjXft-jH.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/chunks/main-CSZrZE1o.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/chunks/main-CSZrZE1o.jsView on unpkg · L9Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunks/main-CSZrZE1o.jsView on unpkg · L1Source appears to collect browser login credentials for exfiltration.
dist/chunks/esm-CsGLyWmS.jsView on unpkg · L1