Leviathan Shel HaShem — the 708-agent Kabbalistic swarm in your terminal. Self-contained binary, no Python/Node deps.
An explicit invocation of one of the package's CLI commands fetches a remote native binary and executes it. The binary is fetched over HTTP, follows unrestricted redirects, and has no signature or checksum verification.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/run.jsView on unpkg · L7Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/run.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/run.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/run.jsView on unpkgPackage ships compressed or archive-like blobs.
leviathan-of-hashem-3.14.3.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
leviathan-of-hashem-3.14.3.tgzView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/run.jsView on unpkg · L7Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/run.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/run.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/run.jsView on unpkgPackage ships compressed or archive-like blobs.
leviathan-of-hashem-3.14.3.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
leviathan-of-hashem-3.14.3.tgzView on unpkg