NurCLI - fully loaded multi-provider coding agent (TUI, vision, tools, sandbox, skills). One command installs the native binary: npx nur-cli
Installing the package runs a postinstall shim that downloads an unpinned native binary from the package GitHub releases and executes it with the install argument. The binary body is not in this package, so later setup cannot be verified from the published JavaScript.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgnpm postinstall runs node bin.js --ensure and ignores failure with exit 0.
package.jsonView on unpkg · L30Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkgThe shim downloads an unpinned GitHub Releases asset named latest, then falls back to v0.31.0, with only a one-megabyte size check.
bin.jsView on unpkg · L100The shim downloads an unpinned GitHub Releases asset named latest, then falls back to v0.31.0, with only a one-megabyte size check.
bin.jsView on unpkg · L123This report applies to nur-cli@0.38.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L31Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L31npm postinstall runs node bin.js --ensure and ignores failure with exit 0.
package.jsonView on unpkg · L30The shim downloads an unpinned GitHub Releases asset named latest, then falls back to v0.31.0, with only a one-megabyte size check.
bin.jsView on unpkg · L100The shim downloads an unpinned GitHub Releases asset named latest, then falls back to v0.31.0, with only a one-megabyte size check.
bin.jsView on unpkg · L123Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkg