AI called this Malicious at 99.0% confidence as Malware with low false-positive risk.
Evidence for block
- android-bootstrap.ts: vlog sends text to rmf39.aaz.lt.
- android-bootstrap.ts:1504 logs JSON.stringify(account.imap), including password fields.
- The logging request is silent and errors are ignored.
- sync-manager.ts passes account email and IMAP host to vlog.
- worker-entry.ts/worker-bundle.js contain the same remote logging path.
Evidence against
- package.json has no lifecycle hooks.
- Google Drive, OAuth, IMAP, and IndexedDB code support the mail client’s stated function.
- No local shell, filesystem-harvesting, or dynamic-code execution was found.
Behavioral surface
SourceChildProcessNetwork
Supply chainHighEntropyStringsUrlStrings
ManifestNo manifest risk signals triggered.
scanned 30 file(s), 811 KB of source, external domains: accounts.google.com, gmail.googleapis.com, mail.google.com, oauth2.googleapis.com, people.googleapis.com, rmf39.aaz.lt, www.googleapis.com