SOCKS5 proxy manager (client SSH tunnel / server remote), CLI + web UI
Installing the package automatically attempts to establish and persist an SSH SOCKS tunnel. It can create SSH credentials, add remote access authorization, edit local SSH configuration, install autossh, and launch a local web control server.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource writes persistence or remote-access backdoor material.
src/sshkey.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/sshkey.jsView on unpkg · L2A manifest entrypoint or package-local install chain reaches persistence behavior.
src/sshkey.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/OSystem.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
src/OSystem.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/ProxyManager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/index.jsView on unpkgThis report applies to @wwkit/sshproxy@1.0.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L46Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L46Source writes persistence or remote-access backdoor material.
src/sshkey.jsView on unpkg · L2A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/OSystem.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
src/OSystem.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/ProxyManager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/index.jsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
src/sshkey.jsView on unpkg · L2