Reusable investment utilities, trading agents, prediction-market analysis (PredictOS core) and financial data tools
No concrete malicious attack was identified in the inspected flagged paths. The credential uses shown are directed to their corresponding services, while trading and wallet-payment capabilities depend on configured keys.
The AI recommended clean. Static policy retained a warning. The static scanner classified the package as malicious with confidence of at least 85%. A critical static finding has confidence of at least 90%. These conditions do not mean that the AI confirmed malicious behavior.
Package contains a possible secret pattern.
dist/index-CLlAnStL-B7EBGdAY.cjsView on unpkg · L1Package source references dynamic code evaluation.
dist/archiver-web.es-B69gABHP.jsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
dist/index-_V1Ql5Es.cjsView on unpkg · L1Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index-_V1Ql5Es.cjsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index-_V1Ql5Es.cjsView on unpkg · L1Source uses private key material to transfer cryptocurrency funds.
dist/polymarket-updown-15-limit-order-bot-DCC8HE9Z.cjsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/predictos/data/kalshi.mjsView on unpkg · L1A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/predictos/data/kalshi.mjsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/index-D7fsk2gy.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/bookmakerAnalysis-CHn1W8uX.cjsView on unpkgHardcoded password in dist/index-CLlAnStL-C554ZmGF.js
dist/index-CLlAnStL-C554ZmGF.jsView on unpkg · L1This report applies to investing@0.1.175.
See version security history for other recorded verdicts.
Evidence last updated: .
Package contains a possible secret pattern.
dist/index-CLlAnStL-B7EBGdAY.cjsView on unpkg · L1Source appears to send environment or credential material to an external endpoint.
dist/index-_V1Ql5Es.cjsView on unpkg · L1Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index-_V1Ql5Es.cjsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/index-D7fsk2gy.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
dist/bookmakerAnalysis-CHn1W8uX.cjsView on unpkgPackage source references dynamic code evaluation.
dist/archiver-web.es-B69gABHP.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index-_V1Ql5Es.cjsView on unpkg · L1Source uses private key material to transfer cryptocurrency funds.
dist/polymarket-updown-15-limit-order-bot-DCC8HE9Z.cjsView on unpkg · L1A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/predictos/data/kalshi.mjsView on unpkg · L1A manifest entrypoint or package-local install chain reaches credential exfiltration behavior.
dist/predictos/data/kalshi.mjsView on unpkg · L1Hardcoded password in dist/index-CLlAnStL-C554ZmGF.js
dist/index-CLlAnStL-C554ZmGF.jsView on unpkg · L1