Static analysis flagged 15 finding(s) at 97.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
bin/kalamasha-tool.jsView on unpkg · L2This report applies to exiouss@2.0.20.
See version security history for other recorded verdicts.
Evidence last updated: .
Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/kalamasha-tool.jsView on unpkg · L2Package source invokes a package manager install command at runtime.
bin/kalamasha-tool.jsView on unpkg · L66Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/kalamasha-tool.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/chrome_cookies.ps1View on unpkgInstall-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
bin/kalamasha-tool.jsView on unpkg · L2Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
bin/kalamasha-tool.jsView on unpkg · L2Package source invokes a package manager install command at runtime.
bin/kalamasha-tool.jsView on unpkg · L66Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/kalamasha-tool.jsView on unpkgPackage ships non-JavaScript build or shell helper files.
bin/chrome_cookies.ps1View on unpkg