NurCLI - fully loaded multi-provider coding agent (TUI, vision, tools, sandbox, skills). One command installs the native binary: npx nur-cli
On npm install, postinstall can download an unsigned native binary from GitHub Releases and run it with install, writing under the user home bin directory. The native payload is not in this package, so its install behavior cannot be verified here.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgpostinstall runs node bin.js --ensure || exit 0, so npm install can download and execute a native binary without failing the install.
package.jsonView on unpkg · L30Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkgpostinstall runs node bin.js --ensure || exit 0, so npm install can download and execute a native binary without failing the install.
bin.jsView on unpkg · L151bin.js fetches GitHub Release assets for nuroctane/nur-cli (latest, then v0.31.0) with no checksum or signature check.
bin.jsView on unpkg · L22This report applies to nur-cli@0.36.9.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L31Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L31postinstall runs node bin.js --ensure || exit 0, so npm install can download and execute a native binary without failing the install.
package.jsonView on unpkg · L30bin.js fetches GitHub Release assets for nuroctane/nur-cli (latest, then v0.31.0) with no checksum or signature check.
bin.jsView on unpkg · L22postinstall runs node bin.js --ensure || exit 0, so npm install can download and execute a native binary without failing the install.
bin.jsView on unpkg · L151Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkg