← Home

@posthog/agent

TypeScript agent framework wrapping Claude Agent SDK with Git-based task execution for PostHog

51
Versions
SEE LICENSE IN LICENSE
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

twixesfuziontechmariusandraben-posthogtimglrafael_posthogfraserhoppermanoelposthogrobbie-cgustavostrassburgerdustinbyrnefeliperalmeidalucasheriquesfrankposthogtom-posthogadamleithpcat-phsarahxsanderspeterkirkhamposthogioannisjjoshuasnyderhuguespouillot

Keywords

posthogclaudeagentaigittypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Expected artifact of trusted-publisher GitHub Actions flow with SLSA attestation. ai
source-diff bulk-net-exec-files:dist AI (source-diff): Bundled tsup build output, not obfuscation or exfil. ai
semgrep semgrep:env-bulk-read AI (semgrep): Function deletes env keys after sanitizing; defensive, not exfil. ai
source-diff bulk-obfuscated-files:dist AI (source-diff): Minified bundler output, no malicious behavior found. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Localhost URL in test mock, not a real network destination. ai
publish-pattern rapid-publish AI (publish-pattern): High-cadence CI publishing is normal for this monorepo package. ai
source-diff large-new-source-files AI (source-diff): Same vendoring event as size increase. ai
source-diff source-size-tripled AI (source-diff): Explained by vendoring Claude CLI + native binaries for stated purpose. ai
maintainer-change maintainer-removed AI (maintainer-change): Intra-org PostHog maintainer rotation. ai
phantom-deps phantom-dep:@openai/codex AI (phantom-deps): Referenced via config/binary invocation, consistent with new codex adapter. ai
provenance publisher-changed AI (provenance): Move to GitHub Actions CI publisher is a provenance improvement, not compromise. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers are PostHog org members, consistent with internal team rotation. ai
source-diff obfuscated-file:dist/claude-cli/cli.js AI (source-diff): Bundled official Anthropic Claude CLI, minified build output not obfuscated malware. ai
phantom-deps phantom-dep:dotenv AI (phantom-deps): Config-only usage, common false positive. ai
source-diff net-exec-file:dist/claude-cli/cli.js AI (source-diff): Same official Claude CLI bundle; network+exec is its documented function. ai
provenance slsa-provenance AI (provenance): PostHog publishes via CI with SLSA attestation consistently; stable signal for this package. ai
phantom-deps phantom-dep:ajv AI (phantom-deps): ajv is a declared runtime dependency; phantom-dep heuristic false positive. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decode in handoff-checkpoint.ts is for deserializing checkpoint file content, not obfuscated payload execution. ai
semgrep semgrep:env-spread AI (semgrep): Spreading process.env to pass environment to Claude CLI subprocess is expected behavior for this agent wrapper. ai
npm-metadata bundled-binaries AI (npm-metadata): Ripgrep and audio-capture binaries are vendored for Claude CLI subprocess use; consistent with package purpose and SLSA-attested build. ai
phantom-deps phantom-dep:@types/jsonwebtoken AI (phantom-deps): @types/jsonwebtoken listed as runtime dep alongside jsonwebtoken; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:yoga-wasm-web AI (phantom-deps): Platform-specific binary dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:tar AI (phantom-deps): tar is a declared runtime dependency; phantom-dep heuristic false positive. ai

Versions (showing 51 of 73)

View all versions
Version Deps Published
2.3.1531 24 / 11
2.3.1529 24 / 11
2.3.1501 21 / 10
2.3.1490 21 / 10
2.3.1486 21 / 10
2.3.1481 21 / 10
2.3.1477 21 / 10
2.3.1476 21 / 10
2.3.1469 21 / 10
2.3.1468 21 / 10
2.3.736 19 / 10
2.3.735 19 / 10
2.3.727 19 / 10
2.3.709 19 / 10
2.3.696 19 / 10
2.3.678 19 / 10
2.3.670 19 / 10
2.3.658 19 / 10
2.3.616 19 / 10
2.3.556 19 / 10
2.3.478 19 / 10
2.3.474 19 / 10
2.3.459 19 / 10
2.3.425 19 / 10
2.3.326 19 / 9
2.3.316 19 / 9
2.3.312 19 / 9
2.3.308 19 / 9
2.3.306 19 / 9
2.3.305 19 / 9
2.3.304 19 / 9
2.3.302 19 / 9
2.3.298 19 / 9
2.3.297 19 / 9
2.3.293 19 / 9
2.3.286 19 / 9
2.3.285 19 / 9
2.3.67 18 / 9
2.3.62 18 / 9
2.3.53 18 / 9
2.3.46 18 / 9
2.3.43 18 / 9
2.3.31 18 / 9
2.3.24 18 / 9
2.3.22 18 / 9
2.3.21 18 / 9
2.3.18 18 / 9
2.3.15 18 / 9
2.3.13 18 / 9
2.3.11 18 / 9
2.3.10 18 / 9

v2.3.1531

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.1529

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.1501

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.1490

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.1486

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.1481

4 findings
HIGH shady-links-raw-ip: src/server/agent-server.test.ts:1504 semgrep

HTTP request to raw IP address — legitimate packages use domain names 1502 | type: "http", 1503 | name: "slack", > 1504 | url: "http://127.0.0.1:5555/relay/slack", 1505 | headers: [{ name: "Authorization", value: "Bearer secret" }], 1506 | };

HIGH shady-links-raw-ip: src/server/agent-server.test.ts:1539 semgrep

HTTP request to raw IP address — legitimate packages use domain names 1537 | type: "http", 1538 | name: "slack", > 1539 | url: "http://127.0.0.1:5555/relay/slack", 1540 | headers: [], 1541 | },

HIGH shady-links-raw-ip: src/server/agent-server.test.ts:1550 semgrep

HTTP request to raw IP address — legitimate packages use domain names 1548 | type: "http", 1549 | name: "slack", > 1550 | url: "http://127.0.0.1:5555/relay/slack", 1551 | headers: [], 1552 | },

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.1477

4 findings
HIGH shady-links-raw-ip: src/server/agent-server.test.ts:1504 semgrep

HTTP request to raw IP address — legitimate packages use domain names 1502 | type: "http", 1503 | name: "slack", > 1504 | url: "http://127.0.0.1:5555/relay/slack", 1505 | headers: [{ name: "Authorization", value: "Bearer secret" }], 1506 | };

HIGH shady-links-raw-ip: src/server/agent-server.test.ts:1539 semgrep

HTTP request to raw IP address — legitimate packages use domain names 1537 | type: "http", 1538 | name: "slack", > 1539 | url: "http://127.0.0.1:5555/relay/slack", 1540 | headers: [], 1541 | },

HIGH shady-links-raw-ip: src/server/agent-server.test.ts:1550 semgrep

HTTP request to raw IP address — legitimate packages use domain names 1548 | type: "http", 1549 | name: "slack", > 1550 | url: "http://127.0.0.1:5555/relay/slack", 1551 | headers: [], 1552 | },

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.1476

4 findings
HIGH shady-links-raw-ip: src/server/agent-server.test.ts:1504 semgrep

HTTP request to raw IP address — legitimate packages use domain names 1502 | type: "http", 1503 | name: "slack", > 1504 | url: "http://127.0.0.1:5555/relay/slack", 1505 | headers: [{ name: "Authorization", value: "Bearer secret" }], 1506 | };

HIGH shady-links-raw-ip: src/server/agent-server.test.ts:1539 semgrep

HTTP request to raw IP address — legitimate packages use domain names 1537 | type: "http", 1538 | name: "slack", > 1539 | url: "http://127.0.0.1:5555/relay/slack", 1540 | headers: [], 1541 | },

HIGH shady-links-raw-ip: src/server/agent-server.test.ts:1550 semgrep

HTTP request to raw IP address — legitimate packages use domain names 1548 | type: "http", 1549 | name: "slack", > 1550 | url: "http://127.0.0.1:5555/relay/slack", 1551 | headers: [], 1552 | },

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.1469

4 findings
HIGH shady-links-raw-ip: src/server/agent-server.test.ts:1504 semgrep

HTTP request to raw IP address — legitimate packages use domain names 1502 | type: "http", 1503 | name: "slack", > 1504 | url: "http://127.0.0.1:5555/relay/slack", 1505 | headers: [{ name: "Authorization", value: "Bearer secret" }], 1506 | };

HIGH shady-links-raw-ip: src/server/agent-server.test.ts:1539 semgrep

HTTP request to raw IP address — legitimate packages use domain names 1537 | type: "http", 1538 | name: "slack", > 1539 | url: "http://127.0.0.1:5555/relay/slack", 1540 | headers: [], 1541 | },

HIGH shady-links-raw-ip: src/server/agent-server.test.ts:1550 semgrep

HTTP request to raw IP address — legitimate packages use domain names 1548 | type: "http", 1549 | name: "slack", > 1550 | url: "http://127.0.0.1:5555/relay/slack", 1551 | headers: [], 1552 | },

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.1468

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.67

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/claude-cli/cli.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/claude-cli/cli.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: timgl → GitHub Actions (on 2026-03-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.3.62

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/claude-cli/cli.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/claude-cli/cli.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: timgl → GitHub Actions (on 2026-03-21, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-21, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.3.53

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/claude-cli/cli.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/claude-cli/cli.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: timgl → GitHub Actions (on 2026-03-20, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.3.46

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/claude-cli/cli.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/claude-cli/cli.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: timgl → GitHub Actions (on 2026-03-17, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-17, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.3.43

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/claude-cli/cli.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/claude-cli/cli.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: timgl → GitHub Actions (on 2026-03-17, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-17, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.3.31

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/claude-cli/cli.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/claude-cli/cli.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: timgl → GitHub Actions (on 2026-03-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.3.24

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/claude-cli/cli.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/claude-cli/cli.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: timgl → GitHub Actions (on 2026-03-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.3.22

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/claude-cli/cli.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/claude-cli/cli.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: timgl → GitHub Actions (on 2026-03-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.3.21

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/claude-cli/cli.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/claude-cli/cli.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: timgl → GitHub Actions (on 2026-03-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.3.18

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/claude-cli/cli.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/claude-cli/cli.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: timgl → GitHub Actions (on 2026-03-13, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.3.15

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/claude-cli/cli.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/claude-cli/cli.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: timgl → GitHub Actions (on 2026-03-13, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.3.13

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/claude-cli/cli.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/claude-cli/cli.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: timgl → GitHub Actions (on 2026-03-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.3.11

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/claude-cli/cli.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/claude-cli/cli.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: timgl → GitHub Actions (on 2026-03-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.3.10

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/claude-cli/cli.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/claude-cli/cli.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: timgl → GitHub Actions (on 2026-03-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (timgl) on 2026-03-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.