3Source sends the broad process environment to a literal external destination.
L3: // src/cli/index.ts
L4: import { createServer as createServer2 } from "http";
L5: import { chmodSync as chmodSync2, createWriteStream, existsSync as existsSync14, mkdirSync as mkdirSync2 } from "fs";
...
L8: import { isAbsolute as isAbsolute13, join as join31, resolve as resolve8 } from "path";
L9: import { spawn as spawn9 } from "child_process";
L10: import { createInterface as createInterface2 } from "readline/promises";
...
L34: function needsCmdExeWrapper(command) {
L35: if (process.platform !== "win32") {
L36: return false;
...
L50: return {
L51: command: "cmd.exe",
L52: args: ["/d", "/s", "/c", [quoteCmdExeArg(command), ...args.map((arg) => quoteCmdExeArg(arg))].join(" ")]
CriticalHardcoded Runtime Data Exfiltration
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist-cli/index.jsView on unpkg · L3 3Trigger-reachable chain: manifest.bin -> dist-cli/index.js
L3: // src/cli/index.ts
L4: import { createServer as createServer2 } from "http";
L5: import { chmodSync as chmodSync2, createWriteStream, existsSync as existsSync14, mkdirSync as mkdirSync2 } from "fs";
...
L8: import { isAbsolute as isAbsolute13, join as join31, resolve as resolve8 } from "path";
L9: import { spawn as spawn9 } from "child_process";
L10: import { createInterface as createInterface2 } from "readline/promises";
...
L34: function needsCmdExeWrapper(command) {
L35: if (process.platform !== "win32") {
L36: return false;
...
L50: return {
L51: command: "cmd.exe",
L52: args: ["/d", "/s", "/c", [quoteCmdExeArg(command), ...args.map((arg) => quoteCmdExeArg(arg))].join(" ")]
CriticalTrigger Reachable Dangerous Capability
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist-cli/index.jsView on unpkg · L3 50return {
L51: command: "cmd.exe",
L52: args: ["/d", "/s", "/c", [quoteCmdExeArg(command), ...args.map((arg) => quoteCmdExeArg(arg))].join(" ")]
3Manifest entrypoint (manifest.bin) carries capability families absent from dist/build output: environment+network, sensitive-file+network, execution+network
L3: // src/cli/index.ts
L4: import { createServer as createServer2 } from "http";
L5: import { chmodSync as chmodSync2, createWriteStream, existsSync as existsSync14, mkdirSync as mkdirSync2 } from "fs";
...
L8: import { isAbsolute as isAbsolute13, join as join31, resolve as resolve8 } from "path";
L9: import { spawn as spawn9 } from "child_process";
L10: import { createInterface as createInterface2 } from "readline/promises";
...
L34: function needsCmdExeWrapper(command) {
L35: if (process.platform !== "win32") {
L36: return false;
...
L50: return {
L51: command: "cmd.exe",
L52: args: ["/d", "/s", "/c", [quoteCmdExeArg(command), ...ar
HighEntrypoint Build Divergence
Manifest entrypoint contains risky behavior absent from dist/build output.
dist-cli/index.jsView on unpkg · L3 •Manifest-reachable source captures an API credential, sends it to a fixed unofficial gateway, and persists that redirection in agent or shell configuration.
dist-cli/index.js:
import { readFile as readFile19, stat as stat18, writeFile as writeFile18 } from "fs/promises";
import { createInterface as createInterface2 } from "readline/promises";
const explicit = process.env.CODEXUI_CODEX_COMMAND?.trim();
const explicit = process.env.CODEXUI_RG_COMMAND?.trim();
const candidate = normalizeRuntimeValue(process.env.CODEXUI_SANDBOX_MODE);
const candidate = normalizeRuntimeValue(process.env.CODEXUI_APPROVAL_POLICY);
const codexHome = process.env.CODEX_HOME?.trim() ?? "";
return codexHome && codexHome.length > 0 ? codexHome : join2(homedir2(), ".codex");
HighCredential Redirect Persistence
Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist-cli/index.jsView on unpkg 3// src/cli/index.ts
L4: import { createServer as createServer2 } from "http";
L5: import { chmodSync as chmodSync2, createWriteStream, existsSync as existsSync14, mkdirSync as mkdirSync2 } from "fs";
...
L8: import { isAbsolute as isAbsolute13, join as join31, resolve as resolve8 } from "path";
L9: import { spawn as spawn9 } from "child_process";
L10: import { createInterface as createInterface2 } from "readline/promises";
...
L34: function needsCmdExeWrapper(command) {
L35: if (process.platform !== "win32") {
L36: return false;
...
L50: return {
L51: command: "cmd.exe",
L52: args: ["/d", "/s", "/c", [quoteCmdExeArg(command), ...args.map((arg) => quoteCmdExeArg(arg))].join(" ")]
HighCommand Output Exfiltration
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist-cli/index.jsView on unpkg · L3 3Detached bundled service listener: dist-cli/index.js launches a Node helper and exposes a broad-bound HTTP listener.
L3: // src/cli/index.ts
L4: import { createServer as createServer2 } from "http";
L5: import { chmodSync as chmodSync2, createWriteStream, existsSync as existsSync14, mkdirSync as mkdirSync2 } from "fs";
...
L8: import { isAbsolute as isAbsolute13, join as join31, resolve as resolve8 } from "path";
L9: import { spawn as spawn9 } from "child_process";
L10: import { createInterface as createInterface2 } from "readline/promises";
...
L34: function needsCmdExeWrapper(command) {
L35: if (process.platform !== "win32") {
L36: return false;
...
L50: return {
L51: command: "cmd.exe",
L52: args: ["/d", "/s", "/c", [quoteCmdExeArg(command), ...args.map((arg) => quoteCmdExeArg(arg))].jo
HighSpawned Bundled Service Listener
Source launches a detached bundled service that exposes a broad-bound HTTP listener.
dist-cli/index.jsView on unpkg · L3 •matchType = normalized_sha256
matchedPackage = codex-mobile-re@0.1.120
matchedPath = dist-cli/index.js
matchedIdentity = npm:Y29kZXgtbW9iaWxlLXJl:0.1.120
similarity = 1.000
summary = normalized source hash matched finalized malicious source
HighKnown Malware Source Similarity
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist-cli/index.jsView on unpkg 15753patternName = generic_password
severity = medium
line = 15753
3// src/cli/index.ts
L4: import { createServer as createServer2 } from "http";
L5: import { chmodSync as chmodSync2, createWriteStream, existsSync as existsSync14, mkdirSync as mkdirSync2 } from "fs";
...
L8: import { isAbsolute as isAbsolute13, join as join31, resolve as resolve8 } from "path";
L9: import { spawn as spawn9 } from "child_process";
L10: import { createInterface as createInterface2 } from "readline/promises";
...
L34: function needsCmdExeWrapper(command) {
L35: if (process.platform !== "win32") {
L36: return false;
...
L50: return {
L51: command: "cmd.exe",
L52: args: ["/d", "/s", "/c", [quoteCmdExeArg(command), ...args.map((arg) => quoteCmdExeArg(arg))].join(" ")]
LowWeak Crypto
Package source references weak cryptographic algorithms.
dist-cli/index.jsView on unpkg · L3