Omnirush — free daily tokens for the most powerful coding model on earth.
The auth module can forward an Omnirush access token to a caller-selected manager origin. This creates conditional credential exposure when an operator configures an untrusted origin.
Package source references child process execution.
core/dist/bundle/chunks/chunk-7ZC4UXSL.jsView on unpkg · L1Package source references shell execution.
core/dist/bundle/chunks/chunk-CMRUVXTE.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
core/dist/bundle/chunks/chunk-CMRUVXTE.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/bundle/chunks/chunk-CMRUVXTE.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
core/deps/photon-node/photon_rs_bg.jsView on unpkg · L4215Package source references dynamic require/import behavior.
core/dist/bundle/chunks/chunk-S7SZN6Z3.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
core/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L35Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
core/dist/bundle/chunks/kimi-coding.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/bundle/chunks/kimi-coding.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
assets/extensions/omnirush/auth.jsView on unpkg · L9Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
src/opencode-config.jsView on unpkgPackage ships WebAssembly modules.
core/deps/photon-node/photon_rs_bg.wasmView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
assets/extensions/omnirush/agents-lib.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
assets/extensions/omnirush/agents-lib.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
assets/extensions/omnirush/voice/capture.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
assets/extensions/omnirush/mcp-client.bundle.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
assets/extensions/omnirush/memory-lib.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/bundle/chunks/chunk-FUXEF6JQ.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/bundle/chunks/https-proxy-agent-2VXB7436.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/bundle/chunks/anthropic.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/bundle/chunks/chunk-NUHFSC37.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/bundle/chunks/openai-codex.jsView on unpkgThis report applies to omnirush@2.2.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
Source reaches cloud instance metadata or link-local credential endpoints.
core/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkgPackage source references weak cryptographic algorithms.
core/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L1Package source references child process execution.
core/dist/bundle/chunks/chunk-7ZC4UXSL.jsView on unpkg · L1Package source references shell execution.
core/dist/bundle/chunks/chunk-CMRUVXTE.jsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
core/dist/bundle/chunks/chunk-CMRUVXTE.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
core/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L35Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
assets/extensions/omnirush/auth.jsView on unpkg · L9Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
src/opencode-config.jsView on unpkgPackage ships WebAssembly modules.
core/deps/photon-node/photon_rs_bg.wasmView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
assets/extensions/omnirush/agents-lib.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
assets/extensions/omnirush/agents-lib.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
assets/extensions/omnirush/voice/capture.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
assets/extensions/omnirush/mcp-client.bundle.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
assets/extensions/omnirush/memory-lib.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/bundle/chunks/chunk-FUXEF6JQ.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/bundle/chunks/https-proxy-agent-2VXB7436.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/bundle/chunks/anthropic.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/bundle/chunks/chunk-NUHFSC37.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/bundle/chunks/openai-codex.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/bundle/chunks/chunk-CMRUVXTE.jsView on unpkgPackage source references a known benign dynamic code generation pattern.
core/deps/photon-node/photon_rs_bg.jsView on unpkg · L4215Package source references dynamic require/import behavior.
core/dist/bundle/chunks/chunk-S7SZN6Z3.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
Source reaches cloud instance metadata or link-local credential endpoints.
core/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkgPackage source references weak cryptographic algorithms.
core/dist/bundle/chunks/bedrock-converse-stream.jsView on unpkg · L1Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
core/dist/bundle/chunks/kimi-coding.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
core/dist/bundle/chunks/kimi-coding.jsView on unpkg