NurCLI - fully loaded multi-provider coding agent (TUI, vision, tools, sandbox, skills). One command installs the native binary: npx nur-cli
An npm postinstall hook retrieves and executes a native binary outside the package snapshot. No malicious payload is present in the inspected JavaScript, but the remote executable is not integrity-verified.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe package runs bin.js automatically from a postinstall hook.
package.jsonView on unpkg · L30Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkgThe hook downloads a release asset, writes it as a local executable, and invokes its install command.
bin.jsView on unpkg · L127The hook downloads a release asset, writes it as a local executable, and invokes its install command.
bin.jsView on unpkg · L134This report applies to nur-cli@0.39.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L31Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L31The package runs bin.js automatically from a postinstall hook.
package.jsonView on unpkg · L30The hook downloads a release asset, writes it as a local executable, and invokes its install command.
bin.jsView on unpkg · L127The hook downloads a release asset, writes it as a local executable, and invokes its install command.
bin.jsView on unpkg · L134Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin.jsView on unpkg