Claude Code Hook -> 本地常驻 Daemon 的状态/持久化底座
After installation and Claude hook activation, a persistent daemon collects local Claude work-session data and automatically exfiltrates reports to a hard-coded external IP. Reporting is enabled by default without an endpoint choice at setup.
Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/launcher.cjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/launcher.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/install/bun.tsView on unpkgPackage source references weak cryptographic algorithms.
src/shared/id.tsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/install.cjsView on unpkg · L1Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/install.cjsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
ui/components/SettingsModule.tsxView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/shared/updater.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/shared/daemonctl.tsView on unpkgPackage source invokes a package manager install command at runtime.
dist/install.cjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/install.cjsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
bin/launcher.cjsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/launcher.cjsView on unpkgPackage source references weak cryptographic algorithms.
src/shared/id.tsView on unpkg · L1Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
ui/components/SettingsModule.tsxView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/shared/updater.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/shared/daemonctl.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/install/bun.tsView on unpkgA single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/install.cjsView on unpkg · L1Package source invokes a package manager install command at runtime.
dist/install.cjsView on unpkg · L2Runtime or CLI source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/install.cjsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/install.cjsView on unpkg