Reusable investment utilities, trading agents, prediction-market analysis (PredictOS core) and financial data tools
No attack surface was identified in the inspected entrypoints. Network calls are runtime financial-data and model-service integrations.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
Package contains a possible secret pattern.
dist/index-CLlAnStL-B7EBGdAY.cjsView on unpkg · L1Package source references dynamic code evaluation.
dist/archiver-web.es-B69gABHP.jsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
dist/index-_V1Ql5Es.cjsView on unpkg · L1Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index-_V1Ql5Es.cjsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index-_V1Ql5Es.cjsView on unpkg · L1Source uses private key material to transfer cryptocurrency funds.
dist/polymarket-updown-15-limit-order-bot-DCC8HE9Z.cjsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/predictos/data/kalshi.mjsView on unpkg · L1A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/predictos/data/kalshi.mjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/index-D7fsk2gy.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/bookmakerAnalysis-CHn1W8uX.cjsView on unpkgHardcoded password in dist/index-CLlAnStL-C554ZmGF.js
dist/index-CLlAnStL-C554ZmGF.jsView on unpkg · L1This report applies to investing@0.1.115.
See version security history for other recorded verdicts.
Evidence last updated: .
Package contains a possible secret pattern.
dist/index-CLlAnStL-B7EBGdAY.cjsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
dist/index-_V1Ql5Es.cjsView on unpkg · L1Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index-_V1Ql5Es.cjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/index-D7fsk2gy.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/bookmakerAnalysis-CHn1W8uX.cjsView on unpkgPackage source references dynamic code evaluation.
dist/archiver-web.es-B69gABHP.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index-_V1Ql5Es.cjsView on unpkg · L1Source uses private key material to transfer cryptocurrency funds.
dist/polymarket-updown-15-limit-order-bot-DCC8HE9Z.cjsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/predictos/data/kalshi.mjsView on unpkg · L1A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/predictos/data/kalshi.mjsView on unpkg · L1Hardcoded password in dist/index-CLlAnStL-C554ZmGF.js
dist/index-CLlAnStL-C554ZmGF.jsView on unpkg · L1