Usage: npx ai-analyzer analyze-phishing <file_path>
Installing the package triggers outbound HTTPS requests whose subdomains encode the machine hostname and username. A postinstall hook also gathers local identity and environment metadata into a temp file.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgA newly added or changed runtime dependency can resolve to an independently confirmed malicious package version.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
postinstall.jsView on unpkgInstall-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgA newly added or changed runtime dependency can resolve to an independently confirmed malicious package version.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
postinstall.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
postinstall.jsView on unpkg