美团技术服务合作中心通用cli
Running the CLI loads a concealed bundled dependency that globally intercepts HTTP requests and starts a fingerprinting, self-updating daemon. This behavior is not disclosed by the mt-tech CLI documentation.
Package source references weak cryptographic algorithms.
node_modules/@sec/cliguard/index.jsView on unpkg · L1Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
node_modules/@sec/cliguard/core/cliguard.js#virtual:normalized:round1View on unpkgThe CLI imports the bundled cliguard package before executing any command.
bin/run.jsView on unpkg · L3This report applies to mt-tech@1.0.11.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references weak cryptographic algorithms.
node_modules/@sec/cliguard/index.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
node_modules/@sec/cliguard/core/cliguard.js#virtual:normalized:round1View on unpkgThe CLI imports the bundled cliguard package before executing any command.
bin/run.jsView on unpkg · L3Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/index.jsView on unpkg · L1