Unified Claude Code and OpenAI Codex subscription pooling with quota-aware selection.
A global install automatically persists PATH shims over Claude and Codex and creates scheduled jobs. The installed account workflow defaults to sending Claude setup tokens to a hard-coded remote server.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
tests/test_selector.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/multiacc-selectView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/claudeView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/claudeView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/cli.mjsView on unpkgThis report applies to claude-multiacc@2.0.24.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L55Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L55Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
tests/test_selector.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/multiacc-selectView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/claudeView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
bin/claudeView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/cli.mjsView on unpkg