Terminal coding agent optimized for DeepSeek V4 prefix cache
No confirmed malicious attack surface was established. The package is a terminal AI coding agent with broad user-invoked capabilities, but inspected install/runtime paths did not show unconsented exfiltration, persistence, destructive behavior, or foreign AI-agent control hijack.
Install-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
dist/chunk-UUUIMCLB.jsView on unpkg · L11Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
dist/chunk-4PD6T2WM.jsView on unpkg · L60Package source references a known benign dynamic code generation pattern.
dist/chunk-4PD6T2WM.jsView on unpkg · L2413Package source references dynamic require/import behavior.
dist/chunk-ROJQUDWP.jsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/chunk-VGM6FTOP.jsView on unpkg · L245Source writes installer persistence such as shell profile or service configuration.
dist/chunk-LBADLVH4.jsView on unpkg · L14Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/chunk-AGYKYPVW.jsView on unpkg · L112Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunk-AGYKYPVW.jsView on unpkg · L112Package ships non-JavaScript build or shell helper files.
completions/rivet.bashView on unpkgPackage contains source files above the static scanner size ceiling.
dist/chunk-EF3XLWYR.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/chunk-EF3XLWYR.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunk-2OLE4JZS.jsView on unpkgInstall-time lifecycle script matches a deterministic static-gate block pattern.
package.jsonView on unpkg · L38Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L38Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/chunk-AGYKYPVW.jsView on unpkg · L112Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/chunk-AGYKYPVW.jsView on unpkg · L112Package ships non-JavaScript build or shell helper files.
completions/rivet.bashView on unpkgPackage contains source files above the static scanner size ceiling.
dist/chunk-EF3XLWYR.jsView on unpkgPackage contains an oversized executable-looking CLI entrypoint.
dist/chunk-EF3XLWYR.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
dist/chunk-2OLE4JZS.jsView on unpkgPackage source references child process execution.
dist/chunk-UUUIMCLB.jsView on unpkg · L11Package source references a known benign dynamic code generation pattern.
dist/chunk-4PD6T2WM.jsView on unpkg · L2413Source contains an obfuscator-style string-array loader that reconstructs and executes hidden code.
dist/chunk-4PD6T2WM.jsView on unpkg · L60Package source references dynamic require/import behavior.
dist/chunk-ROJQUDWP.jsView on unpkg · L1Package source references weak cryptographic algorithms.
dist/chunk-VGM6FTOP.jsView on unpkg · L245Source writes installer persistence such as shell profile or service configuration.
dist/chunk-LBADLVH4.jsView on unpkg · L14