Static Scan Results
scanned 2h ago · by rust-scannerStatic analysis flagged 11 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Static reason
One or more suspicious static signals were detected.
Decision evidence
public snapshotBehavioral surface
ChildProcessEnvironmentVarsEvalFilesystemNetworkShell
HighEntropyStringsUrlStrings
Source & flagged code
4 flagged · loading sourcepackage.jsonView file
•scripts.postinstall = node copy-files.js 2>&1
High
Install Time Lifecycle Scripts
Package defines install-time lifecycle scripts.
package.jsonView on unpkg•scripts.postinstall = node copy-files.js 2>&1
Medium
Ambiguous Install Lifecycle Script
Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgelectron-main.jsView file
264/^(async\s+)?(function\s*(\w*\s*)?\(|\(\)\s*=>|async\s*\(\)\s*=>)/.test(newItem.click.trim()))
L265: try { newItem.click = eval(newItem.click) } catch (_) { }
L266:
Low
Eval
Package source references a known benign dynamic code generation pattern.
electron-main.jsView on unpkg · L264lib/setup.icoView file
•path = lib/setup.ico
kind = high_entropy_blob
sizeBytes = 14040
magicHex = [redacted]
High
Findings
2 High4 Medium5 Low
HighInstall Time Lifecycle Scriptspackage.json
HighShips High Entropy Bloblib/setup.ico
MediumAmbiguous Install Lifecycle Scriptpackage.json
MediumNetwork
MediumEnvironment Vars
MediumStructural Risk Force Deep Review
LowScripts Present
LowEvalelectron-main.js
LowFilesystem
LowHigh Entropy Strings
LowUrl Strings