Critical issue in 1.0.28. Do not use this version. Install @volcengine/ark-cli@1.0.27 or upgrade to a later fixed release.
火山方舟 ARK 平台命令行工具
LPM treats this as warn-only first-party agent extension lifecycle risk. Installing the package downloads and executes an opaque platform binary. Outside CI, that binary is automatically asked to refresh and install Ark skills into local agents.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe package runs a postinstall script during npm installation.
package.jsonView on unpkg · L13Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.jsView on unpkgThe postinstall script downloads a platform binary, verifies its SHA-256 digest, and executes it.
scripts/postinstall.jsView on unpkg · L173This report applies to @volcengine/ark-cli@1.0.28.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L14Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L14The package runs a postinstall script during npm installation.
package.jsonView on unpkg · L13The postinstall script downloads a platform binary, verifies its SHA-256 digest, and executes it.
scripts/postinstall.jsView on unpkg · L173Source file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
scripts/postinstall.jsView on unpkg