@cometix/claude-code-linux-arm64-musl
Claude Code Node.js restored — linux-arm64-musl
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | bundled-binaries | AI (npm-metadata): rg/seccomp are standard Claude Code CLI native deps for linux-arm64-musl target. | ai | |
| source-diff | encoded-string-file:cli.js | AI (source-diff): Minified bundled CLI proxy code, not obfuscation of new malicious payload; matches prior approved sibling. | ai |
Versions (showing 22 of 22)
| Version | Deps | Published |
|---|---|---|
| 2.1.217 | 0 / 0 | |
| 2.1.216 | 0 / 0 | |
| 2.1.215 | 0 / 0 | |
| 2.1.214 | 0 / 0 | |
| 2.1.213 | 0 / 0 | |
| 2.1.212 | 0 / 0 | |
| 2.1.211 | 0 / 0 | |
| 2.1.210 | 0 / 0 | |
| 2.1.209 | 0 / 0 | |
| 2.1.208 | 0 / 0 | |
| 2.1.207 | 0 / 0 | |
| 2.1.206 | 0 / 0 | |
| 2.1.205 | 0 / 0 | |
| 2.1.204 | 0 / 0 | |
| 2.1.203 | 0 / 0 | |
| 2.1.202 | 0 / 0 | |
| 2.1.201 | 0 / 0 | |
| 2.1.200 | 0 / 0 | |
| 2.1.199 | 0 / 0 | |
| 2.1.198 | 0 / 0 | |
| 2.1.196 | 0 / 0 | |
| 0.0.1 | 0 / 0 |
v2.1.217
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.216
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.215
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/ripgrep/arm64-linux/rg • vendor/seccomp/arm64/apply-seccomp
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.214
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/ripgrep/arm64-linux/rg • vendor/seccomp/arm64/apply-seccomp
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.213
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/ripgrep/arm64-linux/rg • vendor/seccomp/arm64/apply-seccomp
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.212
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/ripgrep/arm64-linux/rg • vendor/seccomp/arm64/apply-seccomp
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.211
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/ripgrep/arm64-linux/rg • vendor/seccomp/arm64/apply-seccomp
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.210
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/ripgrep/arm64-linux/rg • vendor/seccomp/arm64/apply-seccomp
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.209
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/seccomp/arm64/apply-seccomp • vendor/ripgrep/arm64-linux/rg
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.208
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/seccomp/arm64/apply-seccomp • vendor/ripgrep/arm64-linux/rg
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.207
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/seccomp/arm64/apply-seccomp • vendor/ripgrep/arm64-linux/rg
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.206
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/seccomp/arm64/apply-seccomp • vendor/ripgrep/arm64-linux/rg
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.205
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/seccomp/arm64/apply-seccomp • vendor/ripgrep/arm64-linux/rg
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.204
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/seccomp/arm64/apply-seccomp • vendor/ripgrep/arm64-linux/rg
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.203
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/seccomp/arm64/apply-seccomp • vendor/ripgrep/arm64-linux/rg
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.202
2 findingsPackage contains compiled binaries that could be backdoors: • vendor/seccomp/arm64/apply-seccomp • vendor/ripgrep/arm64-linux/rg
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.201
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/seccomp/arm64/apply-seccomp • vendor/ripgrep/arm64-linux/rg
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.200
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/seccomp/arm64/apply-seccomp • vendor/ripgrep/arm64-linux/rg
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.199
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/seccomp/arm64/apply-seccomp • vendor/ripgrep/arm64-linux/rg
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.198
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/seccomp/arm64/apply-seccomp • vendor/ripgrep/arm64-linux/rg
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.196
5 findings[Always reject] This version was published by a different npm account than previous versions on 2026-06-30. This could indicate a legitimate maintainer transition or an account compromise.
[Always reject] Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Always reject] Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package contains compiled binaries that could be backdoors: • vendor/seccomp/arm64/apply-seccomp • vendor/ripgrep/arm64-linux/rg
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.