Leviathan Shel HaShem — the 708-agent Kabbalistic swarm in your terminal. Self-contained binary, no Python/Node deps.
The CLI fetches an executable from an unencrypted raw-IP endpoint on first use and after remote-directed updates. It then executes that file without verifying its origin or contents.
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/run.jsView on unpkg · L7Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/run.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/run.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/run.jsView on unpkgPackage ships compressed or archive-like blobs.
leviathan-of-hashem-3.14.3.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
leviathan-of-hashem-3.14.3.tgzView on unpkgThis report applies to leviathan-of-hashem@3.22.0.
See version security history for other recorded verdicts.
Evidence last updated: .
A single source file combines environment access, network access, and code or shell execution; review context before blocking.
bin/run.jsView on unpkg · L7Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/run.jsView on unpkg · L7Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/run.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/run.jsView on unpkgPackage ships compressed or archive-like blobs.
leviathan-of-hashem-3.14.3.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
leviathan-of-hashem-3.14.3.tgzView on unpkg