Hostile 92% javascript Download

gemini-cli-a2a-server 1.0.0

postinstall exfiltrates host data

Install hook host-profile beacon to fixed hostSquat ships upstream manifest link and recon
SHA-2561aa182fe6560d23227ee80f89970bd40503ae9335fff18dfc2faedbd9193d3f3

Also flagged by osv (MAL-2026-14244: Malicious code in gemini-cli-a2a-server (npm)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.