Anyray connect — points local coding tools (Claude Code, Cursor, Windsurf, SDKs) at the Anyray gateway through supported configuration and enrolled personal authentication.
No install-time or import-time attack surface was found. On explicit CLI application, it configures user-selected AI tools to route through a configured Anyray gateway, including an opted-in Copilot seat-token lane.
A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/commands/managed.jsView on unpkg · L56Source writes installer persistence such as shell profile or service configuration.
dist/commands/managed.jsView on unpkg · L56Source appears to send environment or credential material to an external endpoint.
dist/util/copilotSeatToken.jsView on unpkg · L26Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/commands/acpAgent.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/util/vscodeExtension.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/tools/cursor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/util/appQuit.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/util/claudeImporter.jsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
dist/commands/managed.jsView on unpkg · L56Source writes installer persistence such as shell profile or service configuration.
dist/commands/managed.jsView on unpkg · L56Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/commands/acpAgent.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/util/vscodeExtension.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/tools/cursor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/util/appQuit.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/util/claudeImporter.jsView on unpkgSource appears to send environment or credential material to an external endpoint.
dist/util/copilotSeatToken.jsView on unpkg · L26