upbit
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyreferences/setup.md
LOWAnomalyLOW
references/setup.md
The fragment is an operational setup guide, not malware or executable code. It contains no direct malicious behavior, but it introduces supply-chain and credential-handling risk by directing users to install an unverified global npm package and by recommending broad trading and withdrawal permissions. The package itself must be audited before installation, and users should use least-privilege API keys, avoid command-line secret flags, and verify secure permissions on ~/.upbit/config.
Confidence: 96%Severity: 55%
Audit Metadata