Connect to the botfork TUI server over SSH — nothing to install locally.
Installing the package runs a disguised helper that builds and starts a local server, writes user configuration and cache files, and initiates SSH. The supplied probe flag has no handling in the helper.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe postinstall hook automatically launches an executable helper rather than only validating it.
package.jsonView on unpkg · L17Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/botfork.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/botfork.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/postinstall.jsView on unpkgThe postinstall hook automatically launches an executable helper rather than only validating it.
lib/postinstall.jsView on unpkg · L35The helper ignores the claimed probe mode and, on its default path, starts a detached server and attempts an SSH session during installation.
BotFork Shortcut.txtView on unpkg · L300The helper is deliberately disguised as a .txt file and writes a host key, binary, PID, and log under the user's configuration and cache directories.
BotFork Shortcut.txtView on unpkg · L28This report applies to botfork@0.2.19.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L18Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L18The postinstall hook automatically launches an executable helper rather than only validating it.
package.jsonView on unpkg · L17Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/botfork.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/botfork.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/postinstall.jsView on unpkgThe postinstall hook automatically launches an executable helper rather than only validating it.
lib/postinstall.jsView on unpkg · L35The helper ignores the claimed probe mode and, on its default path, starts a detached server and attempts an SSH session during installation.
BotFork Shortcut.txtView on unpkg · L300The helper is deliberately disguised as a .txt file and writes a host key, binary, PID, and log under the user's configuration and cache directories.
BotFork Shortcut.txtView on unpkg · L28