Unified Claude Code and OpenAI Codex subscription pooling with quota-aware selection.
LPM flags this version as an AI-agent control-surface risk. A global npm installation automatically persists shims and recurring jobs that intercept Claude and Codex commands. It changes broad AI-agent command control surfaces before any separate setup command.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
tests/test_selector.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/claude-accountsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/codexView on unpkgThe npm postinstall automatically runs the installer during global installation.
scripts/postinstall.mjsView on unpkg · L19This report applies to claude-multiacc@2.0.28.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L57Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L57Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
tests/test_selector.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/claude-accountsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/codexView on unpkgThe npm postinstall automatically runs the installer during global installation.
scripts/postinstall.mjsView on unpkg · L19