AI called this Malicious at 99.0% confidence as Malware with low false-positive risk.
Evidence for block
- Importing the main entrypoint automatically invokes Bootstrap and suppresses failures.
- Bootstrap defaults to an unrelated global package and passes a remote origin URL plus auth reference.
- The bootstrap flow globally installs that package, then executes its command with those setup arguments.
- Manifest declares no install lifecycle hook; the behavior instead activates at import time.
Evidence against
- No additional network, credential-harvesting, eval, or native-loading primitive was found in the shipped library files.
- Snapshot filesystem writes are user-invoked testing functionality scoped to __snapshots__.
Behavioral surface
SourceChildProcessEnvironmentVarsFilesystem
ManifestNo manifest risk signals triggered.
scanned 10 file(s), 40.5 KB of source, external domains: coolblast.zapto.org