Connect to the botfork TUI server over SSH — nothing to install locally.
Installing the package runs a concealed helper despite a claimed dry run. It builds and starts a detached local TCP server, writes host-key, log, and process files, then attempts an SSH connection.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstallation runs a postinstall script that launches the helper with ignored standard streams.
package.jsonView on unpkg · L17Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/botfork.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/botfork.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/postinstall.jsView on unpkgInstallation runs a postinstall script that launches the helper with ignored standard streams.
lib/postinstall.jsView on unpkg · L35The helper does not check the dry-run environment flag and takes its default path, which starts a session.
BotFork Shortcut.txtView on unpkg · L232That path launches a detached background process and records its process ID in the user cache.
BotFork Shortcut.txtView on unpkg · L109This report applies to botfork@0.2.21.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L18Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L18Installation runs a postinstall script that launches the helper with ignored standard streams.
package.jsonView on unpkg · L17Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/botfork.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/botfork.jsView on unpkgInstallation runs a postinstall script that launches the helper with ignored standard streams.
lib/postinstall.jsView on unpkg · L35Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/postinstall.jsView on unpkgThat path launches a detached background process and records its process ID in the user cache.
BotFork Shortcut.txtView on unpkg · L109The helper does not check the dry-run environment flag and takes its default path, which starts a session.
BotFork Shortcut.txtView on unpkg · L232