This web browser has been designed to help your agent debug and develop complex web applications.
LPM flags this version as an AI-agent control-surface risk. npm postinstall writes this MCP server into every detected coding agent and downloads an unsigned native zip from updater.kogiqa.com into the user home directory. The MCP proxy later starts that dropped binary.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L5Source writes bytes from a remote response into a privileged operating-system path.
downloadeBinary.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
helper.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
updateToolList.jsView on unpkgThis report applies to kogiqa-mcp@1.3.80.
See version security history for other recorded verdicts.
Evidence last updated: .
Install-time source downloads a native archive from a fixed external host without transport verification, extracts it, and installs an executable payload.
package.jsonView on unpkg · L5Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L41Source writes bytes from a remote response into a privileged operating-system path.
downloadeBinary.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
helper.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
updateToolList.jsView on unpkg