Ozaiya agent daemon - server management and terminal
Starting the daemon can collect existing provider OAuth material and forward it to the configured Ozaiya server. No confirmed covert attack was established, but the destination can be overridden without a source-enforced allowlist.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index-BAr5622H.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runGemini-CMUOPIE3.cjsView on unpkgPackage source references dynamic require/import behavior.
dist/runGemini-CMUOPIE3.cjsView on unpkg · L2Source dynamically best-effort loads a bundled native addon.
dist/api-Ji1wSTXt.mjsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/api-Ji1wSTXt.mjsView on unpkg · L1Source decrypts an embedded payload, writes it to disk, and executes it through a child process.
dist/api-D3KLTJ6v.cjsView on unpkgA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/api-D3KLTJ6v.cjsView on unpkg · L2Package ships non-JavaScript build or shell helper files.
bin/ozaiya-local.shView on unpkgPackage ships high-entropy non-source blobs.
tools/archives/difftastic-arm64-linux.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
tools/archives/difftastic-arm64-linux.tar.gzView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index-9XvDsO3v.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index-P2XY8Kjd.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/claude_version_utils.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/config-C3e6HwhY.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runCodex-D5dfYvcw.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/env-wrapper.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runGemini-NyJpDUe6.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/ripgrep_launcher.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/config-Ddiq6B9G.mjsView on unpkgThis report applies to ozaiya-cli@0.11.23.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api-Ji1wSTXt.mjsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/api-Ji1wSTXt.mjsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/api-Ji1wSTXt.mjsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/api-D3KLTJ6v.cjsView on unpkg · L2A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/api-D3KLTJ6v.cjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api-D3KLTJ6v.cjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L101Package source references dynamic require/import behavior.
dist/runGemini-CMUOPIE3.cjsView on unpkg · L2Source dynamically best-effort loads a bundled native addon.
dist/api-Ji1wSTXt.mjsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/api-Ji1wSTXt.mjsView on unpkg · L1Source decrypts an embedded payload, writes it to disk, and executes it through a child process.
dist/api-D3KLTJ6v.cjsView on unpkgA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/api-D3KLTJ6v.cjsView on unpkg · L2Package ships non-JavaScript build or shell helper files.
bin/ozaiya-local.shView on unpkgPackage ships high-entropy non-source blobs.
tools/archives/difftastic-arm64-linux.tar.gzView on unpkgPackage ships compressed or archive-like blobs.
tools/archives/difftastic-arm64-linux.tar.gzView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index-9XvDsO3v.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/index-P2XY8Kjd.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/claude_version_utils.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/config-C3e6HwhY.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runCodex-D5dfYvcw.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/env-wrapper.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runGemini-NyJpDUe6.mjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
scripts/ripgrep_launcher.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/config-Ddiq6B9G.mjsView on unpkgManifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist/index-BAr5622H.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/runGemini-CMUOPIE3.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api-Ji1wSTXt.mjsView on unpkgSource writes installer persistence such as shell profile or service configuration.
dist/api-Ji1wSTXt.mjsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/api-Ji1wSTXt.mjsView on unpkg · L1Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/api-D3KLTJ6v.cjsView on unpkg · L2A manifest entrypoint or package-local install chain reaches persistence behavior.
dist/api-D3KLTJ6v.cjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/api-D3KLTJ6v.cjsView on unpkg