美团技术服务合作中心通用cli
Running the mt-tech CLI imports a bundled, obfuscated guard that alters HTTP handling and launches a recurring daemon. The daemon checks for remote updates and can process downloaded files.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/@sec/cliguard/index.jsView on unpkgPackage source references weak cryptographic algorithms.
node_modules/@sec/cliguard/index.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
node_modules/@sec/cliguard/core/cliguard.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/@sec/cliguard/core/cliguard-wrapper.jsView on unpkgThis report applies to mt-tech@1.0.12.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references weak cryptographic algorithms.
node_modules/@sec/cliguard/index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/@sec/cliguard/index.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
node_modules/@sec/cliguard/core/cliguard.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
node_modules/@sec/cliguard/core/cliguard-wrapper.jsView on unpkgSource contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1