Mobile and Web client for Claude Code and Codex (fork of happy)
On npm installation, the package extracts opaque platform archives into its own tools directory and sets executable permissions. The inspected JavaScript does not establish malicious behavior, but the archive contents cannot be fully source-audited.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
dist/AcpBackend-B7AI9jOb.cjsView on unpkg · L2Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/index-CNvSdAiz.mjsView on unpkg · L3Source writes installer persistence such as shell profile or service configuration.
dist/index-CNvSdAiz.mjsView on unpkg · L3Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index-Dudj3EJb.cjsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
dist/index-Dudj3EJb.cjsView on unpkg · L6Package ships non-JavaScript build or shell helper files.
scripts/download-tools.shView on unpkgPackage ships high-entropy non-source blobs.
tools/archives/difftastic-arm64-linux.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
tools/archives/difftastic-arm64-linux.tar.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/index-BdP_5qxF.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/ripgrep_launcher.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/claude_local_launcher.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib.mjsView on unpkgThis report applies to claudeputer@1.1.50.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L76Package source references dynamic require/import behavior.
dist/AcpBackend-B7AI9jOb.cjsView on unpkg · L2Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/index-CNvSdAiz.mjsView on unpkg · L3Source writes installer persistence such as shell profile or service configuration.
dist/index-CNvSdAiz.mjsView on unpkg · L3Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index-Dudj3EJb.cjsView on unpkgA manifest entrypoint or package-local install chain reaches persistence behavior.
dist/index-Dudj3EJb.cjsView on unpkg · L6Package ships non-JavaScript build or shell helper files.
scripts/download-tools.shView on unpkgPackage ships high-entropy non-source blobs.
tools/archives/difftastic-arm64-linux.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
tools/archives/difftastic-arm64-linux.tar.gzView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/index-BdP_5qxF.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/ripgrep_launcher.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/claude_local_launcher.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/lib.mjsView on unpkg