NurCLI - fully loaded multi-provider coding agent (TUI, vision, tools, sandbox, skills). One command installs the native binary: npx nur-cli
Installing nur-cli runs a postinstall shim that downloads an unsigned native binary from GitHub Releases and executes it. The channel is the moving latest release, with an older fallback tag, and redirects are followed without a signature check.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgnpm postinstall runs node bin.js --ensure and forces a zero exit status.
package.jsonView on unpkg · L31Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkgIf the native binary is missing, --ensure downloads it and runs it with the install argument.
bin.jsView on unpkg · L151Release URLs use GitHub latest/download and fallback tag 0.31.0 rather than package version 0.38.1, with no content hash check.
bin.jsView on unpkg · L22This report applies to nur-cli@0.38.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L31Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L31npm postinstall runs node bin.js --ensure and forces a zero exit status.
package.jsonView on unpkg · L31Release URLs use GitHub latest/download and fallback tag 0.31.0 rather than package version 0.38.1, with no content hash check.
bin.jsView on unpkg · L22If the native binary is missing, --ensure downloads it and runs it with the install argument.
bin.jsView on unpkg · L151Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkg