Hold
chore: add anonymous usage telemetry
Do not merge yet
8 files changed (+51 −3). 32 of 54 lines carry the risk; read them in about 10 minutes, and skim or skip the other 22. Written by Claude Code; no person has committed on top of it.
- 5 threats: install script wired to a malicious module, possible data exfiltration, package registry redirected — payload behaviour in src/telemetry.ts.
- Adds 2 outbound destinations, 2 unrecognised: webhook.site, npm.pkgs-cdn.dev.
- Adds 1 outside vendor: PostHog (analytics).
+51−38 filesWritten by Claude CodeIntent: aligned
Why hold: Install script wired to a malicious module in package.json: An install hook runs on every install, and this change also adds code that fetches remote code or exfiltrates data (src/telemetry.ts). Possible data exfiltration: reads environment variables (L12) → sends to webhook.site (sink) via http (L4) in src/telemetry.ts. 2 critical findings: Install script wired to a malicious module; Possible data exfiltration. Risk 88/100. Policy: default.
You have 15 minutes
A careful read of everything: 16 min32 lines to read9 to skim13 to skip