animade
Warn
Audited by Socket on Sep 13, 2026
1 alert found:
SecuritySecurityscripts/bootstrap.mjs
MEDIUMSecurityMEDIUM
scripts/bootstrap.mjs
This is an automated remote bootstrapper with a significant supply-chain security risk. It contacts a third-party default domain, globally installs an npm package, and executes the resulting CLI. The package metadata is partially validated, but ANIMADE_CLI_PACKAGE bypasses that validation. The fragment does not itself demonstrate malware, data theft, or sabotage, but compromise or untrustworthiness of the origin, npm package, dependencies, or overridden executable could lead to arbitrary code execution with user privileges. Review the domain, package provenance, integrity/signature controls, and whether the environment overrides are trusted before use.
Confidence: 97%Severity: 82%
Audit Metadata