Omnirush — free daily tokens for the most powerful coding model on earth.
LPM treats this as warn-only first-party agent extension lifecycle risk. The CLI copies and activates a package-owned coding-agent extension when the user runs it. No unconsented npm-install-time agent mutation was identified.
Package source references child process execution.
core/dist/bundle/chunks/chunk-7ZC4UXSL.jsView on unpkg · L1Package source references shell execution.
core/dist/bundle/chunks/chunk-CMRUVXTE.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
core/dist/bundle/chunks/chunk-CMRUVXTE.jsView on unpkg · L1Package source references a known benign dynamic code generation pattern.
core/deps/photon-node/photon_rs_bg.jsView on unpkg · L4215Package source references dynamic require/import behavior.
core/dist/bundle/chunks/chunk-S7SZN6Z3.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
core/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L35Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
core/dist/bundle/chunks/kimi-coding.jsView on unpkg · L1Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
assets/extensions/omnirush/auth.jsView on unpkg · L9Package ships WebAssembly modules.
core/deps/photon-node/photon_rs_bg.wasmView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
assets/extensions/omnirush/engine-messages.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/core/export-html/vendor/highlight.min.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/core/export-html/vendor/marked.min.jsView on unpkgThis report applies to omnirush@1.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
Source reaches cloud instance metadata or link-local credential endpoints.
core/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L1Package source references weak cryptographic algorithms.
core/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L1Package source references child process execution.
core/dist/bundle/chunks/chunk-7ZC4UXSL.jsView on unpkg · L1Package source references shell execution.
core/dist/bundle/chunks/chunk-CMRUVXTE.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
core/dist/bundle/chunks/chunk-CMRUVXTE.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
core/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L35Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
assets/extensions/omnirush/auth.jsView on unpkg · L9Package ships WebAssembly modules.
core/deps/photon-node/photon_rs_bg.wasmView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
assets/extensions/omnirush/engine-messages.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/core/export-html/vendor/highlight.min.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/core/export-html/vendor/marked.min.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
core/deps/photon-node/photon_rs_bg.jsView on unpkg · L4215Package source references dynamic require/import behavior.
core/dist/bundle/chunks/chunk-S7SZN6Z3.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
Source reaches cloud instance metadata or link-local credential endpoints.
core/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L1Package source references weak cryptographic algorithms.
core/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L1Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
core/dist/bundle/chunks/kimi-coding.jsView on unpkg · L1