longform-to-content
Warn
Audited by Socket on Aug 13, 2026
1 alert found:
AnomalyAnomalyscripts/gen_thumb_baked.py
LOWAnomalyLOW
scripts/gen_thumb_baked.py
This module itself contains no explicit malware logic (no credential theft, exfiltration, or exploit primitives), but it executes a local command/script located under a user-writable directory (%APPDATA%\npm\higgsfield.cmd) and then downloads remote content to disk based on HTTPS URLs extracted from the command’s untrusted JSON output. The lack of a domain allowlist, signature/content validation, and the “download the last URL” behavior make it a meaningful supply-chain/secondary payload risk if the external tool or its outputs are compromised.
Confidence: 60%Severity: 55%
Audit Metadata