CLI for DesignKit Team Agent
The active CLI loads an obfuscated bundle containing network requests and process inspection. No confirmed attack was established, but destination and authorization behavior remain unresolved.
Package source references dynamic require/import behavior.
bin/designkit-cli.jsView on unpkg · L2A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/index.jsView on unpkg · L1This report applies to meitu-designkit-cli@1.0.71.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
bin/designkit-cli.jsView on unpkg · L2A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/index.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/index.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
dist/index.jsView on unpkg · L1