ltcai12 versions·0.1.29→3.1.0
Lattice AI v3 local-first AI workspace platform with knowledge graph, vector index, hybrid search, agents, and workspace modes.
→ 정적 분석기가 curl-pipe-bash 패턴 검출 — 설치 경로에 원격 코드 실행 형태가 그대로 드러남.
// Data staging
패턴: install-path-npm-publish
Packages whose static analysis matched this pattern. See the per-package detail pages for the offending code excerpt.
23개 패키지에 이 패턴이 매칭됨 (총 publish 이벤트 39건을 publisher+name 기준으로 묶음). 최신순.
Lattice AI v3 local-first AI workspace platform with knowledge graph, vector index, hybrid search, agents, and workspace modes.
→ 정적 분석기가 curl-pipe-bash 패턴 검출 — 설치 경로에 원격 코드 실행 형태가 그대로 드러남.
AI security skills grounded in mid-2026 threat reality, not stale framework documentation. 51 skills, 11 catalogs (439 CVEs / 177 CWEs / 805 ATT&CK + ICS / 170 ATLAS / 468 D3FEND / 8888 RFCs), 35 jurisdictions, 10-class catalog gap detector + budget gate,
→ Worm self-propagation: package reads .npmrc _authToken AND invokes npm publish in install-path code. Shai-Hulud-class shape — no legitimate package re-publishes OTHER packages from the user's machine.
Claws — Terminal Control Bridge for VS Code. One command to install.
→ Worm self-propagation: package reads .npmrc _authToken AND invokes npm publish in install-path code. Shai-Hulud-class shape — no legitimate package re-publishes OTHER packages from the user's machine.
A comprehensive list of all free email domain providers
The `@trackunit/iris-app` package is a plugin for [NX by @nrwl](https://nx.dev/). This plugin adds some helpful generators used to set up a Trackunit Iris App project.
→ Worm self-propagation: package reads .npmrc _authToken AND invokes npm publish in install-path code. Shai-Hulud-class shape — no legitimate package re-publishes OTHER packages from the user's machine.
This template should help get you started developing with Vue 3 in Vite.
→ Worm self-propagation: package reads .npmrc _authToken AND invokes npm publish in install-path code. Shai-Hulud-class shape — no legitimate package re-publishes OTHER packages from the user's machine.
Personal AI assistant powered by Antigravity, AI-E, Claude, Claude E, Codex, Codex App, Cursor, Gemini, Grok, OpenCode, and Copilot — Web, Terminal, Telegram, and Discord interfaces with 107 built-in skills
→ 정적 분석기가 curl-pipe-bash 패턴 검출 — 설치 경로에 원격 코드 실행 형태가 그대로 드러남.
A modified version of the Pokémon Showdown server, designed for PokeBedrock.
→ 크리덴셜 읽기 (reads-azure-creds) + 외부 전송지 pastebin-domain 조합 — 전형적인 유출 패턴.
AI coding agent powered by open-source models (Ollama/vLLM) — interactive TUI with agentic tool-calling loop
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
虾说智能助手
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
AWS CDK security and cost analysis CLI. Free static scans via npm — no account needed. Sign up free to add AI-powered insights.
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
This template provides a minimal setup to get React working in Vite with HMR and some ESLint rules.
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
Core of lint-md which used to lint your markdown file for Chinese.
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
MCP Server for AntV visualization libraries development, which provides documentation context and examples for visualization developers.
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
graph layout algorithm implemented with GPGPU
→ 의심 전송지 없음, 원격 실행 형태 없음 — 2 known-vendor host(s).
L7-React 已全面 升级为 LarkMap,不在进行维护 。 LarkMap 空间数据可视分析组件库
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s), 1 other host(s).
## Getting Started
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
Geographic data editing tool based on L7
A drawing package for L7
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
Using React Component to Define Your G6 Graph Node
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
在线 Demo 地址: https://antv.vision/DipperMap/demo
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s), 1 other host(s).