@cometix/claude-code-win32-x64
Claude Code Node.js restored — win32-x64
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | bundled-binaries | AI (npm-metadata): Native binaries (ripgrep, image/audio processing) are documented deps of this CLI tool. | ai | |
| source-diff | encoded-string-file:cli.js | AI (source-diff): Minified bundle output, unchanged from previously approved sibling version. | ai | |
| source-diff | obfuscated-file:cli.js | AI (source-diff): Bun-bundled Claude Code CLI; long lines are minifier output, not obfuscation. | ai | |
| source-diff | net-exec-file:cli.js | AI (source-diff): CLI legitimately makes network calls and loads native modules; no hostile target. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 2.1.217 | 0 / 0 | |
| 2.1.216 | 0 / 0 | |
| 2.1.215 | 0 / 0 | |
| 2.1.214 | 0 / 0 | |
| 2.1.213 | 0 / 0 | |
| 2.1.212 | 0 / 0 | |
| 2.1.211 | 0 / 0 | |
| 2.1.210 | 0 / 0 | |
| 2.1.209 | 0 / 0 | |
| 2.1.208 | 0 / 0 | |
| 2.1.207 | 0 / 0 | |
| 2.1.206 | 0 / 0 | |
| 2.1.205 | 0 / 0 | |
| 2.1.204 | 0 / 0 | |
| 2.1.203 | 0 / 0 | |
| 2.1.202 | 0 / 0 | |
| 2.1.201 | 0 / 0 | |
| 2.1.200 | 0 / 0 | |
| 2.1.199 | 0 / 0 | |
| 2.1.197 | 0 / 0 | |
| 2.1.196 | 0 / 0 | |
| 2.1.123 | 0 / 0 | |
| 0.0.1 | 0 / 0 |
v2.1.217
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.216
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.215
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/ripgrep/x64-win32/rg.exe • vendor/image-processor/x64-win32/image-processor.node • vendor/audio-capture/x64-win32/audio-capture.node
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.214
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.213
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/ripgrep/x64-win32/rg.exe • vendor/image-processor/x64-win32/image-processor.node • vendor/audio-capture/x64-win32/audio-capture.node
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.212
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/image-processor/x64-win32/image-processor.node • vendor/audio-capture/x64-win32/audio-capture.node • vendor/ripgrep/x64-win32/rg.exe
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.211
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/image-processor/x64-win32/image-processor.node • vendor/audio-capture/x64-win32/audio-capture.node • vendor/ripgrep/x64-win32/rg.exe
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.210
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/image-processor/x64-win32/image-processor.node • vendor/audio-capture/x64-win32/audio-capture.node • vendor/ripgrep/x64-win32/rg.exe
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.209
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/audio-capture/x64-win32/audio-capture.node • vendor/image-processor/x64-win32/image-processor.node • vendor/ripgrep/x64-win32/rg.exe
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.208
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/audio-capture/x64-win32/audio-capture.node • vendor/image-processor/x64-win32/image-processor.node • vendor/ripgrep/x64-win32/rg.exe
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.207
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/audio-capture/x64-win32/audio-capture.node • vendor/image-processor/x64-win32/image-processor.node • vendor/ripgrep/x64-win32/rg.exe
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.206
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/audio-capture/x64-win32/audio-capture.node • vendor/image-processor/x64-win32/image-processor.node • vendor/ripgrep/x64-win32/rg.exe
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.205
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/audio-capture/x64-win32/audio-capture.node • vendor/image-processor/x64-win32/image-processor.node • vendor/ripgrep/x64-win32/rg.exe
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.204
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/audio-capture/x64-win32/audio-capture.node • vendor/image-processor/x64-win32/image-processor.node • vendor/ripgrep/x64-win32/rg.exe
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.203
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/audio-capture/x64-win32/audio-capture.node • vendor/image-processor/x64-win32/image-processor.node • vendor/ripgrep/x64-win32/rg.exe
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.202
2 findingsPackage contains compiled binaries that could be backdoors: • vendor/audio-capture/x64-win32/audio-capture.node • vendor/image-processor/x64-win32/image-processor.node • vendor/ripgrep/x64-win32/rg.exe
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.201
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/audio-capture/x64-win32/audio-capture.node • vendor/image-processor/x64-win32/image-processor.node • vendor/ripgrep/x64-win32/rg.exe
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.200
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/audio-capture/x64-win32/audio-capture.node • vendor/image-processor/x64-win32/image-processor.node • vendor/ripgrep/x64-win32/rg.exe
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.199
3 findingsPackage contains compiled binaries that could be backdoors: • vendor/audio-capture/x64-win32/audio-capture.node • vendor/image-processor/x64-win32/image-processor.node • vendor/ripgrep/x64-win32/rg.exe
Modified file contains 6 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.197
5 findingsPackage contains compiled binaries that could be backdoors: • vendor/audio-capture/x64-win32/audio-capture.node • vendor/image-processor/x64-win32/image-processor.node • vendor/ripgrep/x64-win32/rg.exe
[Reject — re-review on republish] (prior reject: AI (provenance): Publisher change on a young package with no ecosystem trust is a strong account-compromise/hijack signal.) This version was published by a different npm account than previous versions on 2026-06-30. This could indicate a legitimate maintainer transition or an account compromise.
[Reject — re-review on republish] (prior reject: AI (source-diff): 14.5MB minified/obfuscated CLI bundle with no readable source; high-risk pattern for this package.) Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Reject — re-review on republish] (prior reject: AI (source-diff): Network + dynamic code execution in newly added file is a dropper hallmark for this package.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.196
5 findings[Always reject] This version was published by a different npm account than previous versions on 2026-06-30. This could indicate a legitimate maintainer transition or an account compromise.
[Always reject] Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Always reject] Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package contains compiled binaries that could be backdoors: • vendor/audio-capture/x64-win32/audio-capture.node • vendor/image-processor/x64-win32/image-processor.node • vendor/ripgrep/x64-win32/rg.exe
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.123
5 findingsPackage contains compiled binaries that could be backdoors: • vendor/ripgrep/x64-win32/rg.exe • vendor/audio-capture/x64-win32/audio-capture.node
[Reject — re-review on republish] (prior reject: AI (source-diff): 14.5MB minified/obfuscated CLI bundle with no readable source; high-risk pattern for this package.) Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Reject — re-review on republish] (prior reject: AI (source-diff): Network + dynamic code execution in newly added file is a dropper hallmark for this package.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (haleclipse) on 2026-04-29, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.