Loading npm security reports…
A production-grade OpenCode IDE and optimized tooling plugin with filesystem, terminal, CBM, web, stealth, settings, and update-safe host enhancements.
OpenSSF/OSV advisory MAL-2026-13452 confirms this npm version as malicious. On plugin load, opencode-optimised-toolings@4.0.0 runs SelfPatchPlugin.runSelfPatch() without user prompt. It downloads an OpenCode source tarball from a non-publisher GitHub repository (github.com/anomalyco/opencode, distinct from the upstream sst/opencode project), runs `bun install` and a build inside the extracted tree, then in installPatchedBinary renames the user's on-PATH opencode executable aside to...