Unified Claude Code and OpenAI Codex subscription pooling with quota-aware selection.
LPM flags this version as an AI-agent control-surface risk. A global npm install automatically changes shell command resolution for Claude and Codex and creates persistent scheduled jobs. The package also configures a hard-coded remote sync target that can receive Claude setup tokens during account synchronization.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe install lifecycle automatically runs the installer during global npm installation.
package.jsonView on unpkg · L56Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
tests/test_selector.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/claude-accountsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/codexView on unpkgThis report applies to claude-multiacc@2.0.31.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L57Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L57The install lifecycle automatically runs the installer during global npm installation.
package.jsonView on unpkg · L56Package hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
tests/test_selector.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/claude-accountsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/codexView on unpkg