syCode — terminal coding agent + team daemon sidecar for remote monitoring.
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Package source references child process execution.
dist/extensions/sycode-background/src/core/fusion/pi-child.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/fusion/pi-child.jsView on unpkgPackage source references shell execution.
dist/extensions/sycode-mcp-adapter/utils.jsView on unpkg · L108Package source references dynamic code evaluation.
dist/extensions/sycode-background/src/core/anthropic-attribution.jsView on unpkg · L1660Package source references dynamic require/import behavior.
dist/extensions/sycode-mcp-adapter/proxy-modes.jsView on unpkg · L19Package source executes code through a VM context API.
extensions/sycode-mcp-adapter/mcp-script-worker.mjsView on unpkg · L40A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/extensions/sycode-mcp-adapter/ui-session.jsView on unpkg · L83Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-mcp-adapter/ui-session.jsView on unpkgSource downloads or fetches remote code and executes it.
dist/src/cli.jsView on unpkg · L4A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/src/cli.jsView on unpkg · L4Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/src/cloud.jsView on unpkg · L12Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cloud.jsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/extensions/sycode-background/src/core/fusion/web-fetch.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/extensions/sycode-background/src/core/common.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/registry.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-mcp-adapter/mcp-auth.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-background/src/core/registry.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-mcp-adapter/mcp-auth.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-mcp-adapter/request-headers-command.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/daemon-manage.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-background/src/core/fusion/pi-child.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-mcp-adapter/request-headers-command.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/attested-pi-run.jsView on unpkgThis report applies to @synotech/code@1.5.18.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
dist/extensions/sycode-background/src/core/fusion/pi-child.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/fusion/pi-child.jsView on unpkgSource downloads or fetches remote code and executes it.
Source reaches cloud instance metadata or link-local credential endpoints.
dist/extensions/sycode-background/src/core/fusion/web-fetch.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/extensions/sycode-background/src/core/common.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/registry.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-mcp-adapter/mcp-auth.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-background/src/core/registry.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-mcp-adapter/mcp-auth.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-mcp-adapter/request-headers-command.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/daemon-manage.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-background/src/core/fusion/pi-child.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-mcp-adapter/request-headers-command.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/attested-pi-run.jsView on unpkgPackage source references shell execution.
dist/extensions/sycode-mcp-adapter/utils.jsView on unpkg · L108Package source references dynamic code evaluation.
dist/extensions/sycode-background/src/core/anthropic-attribution.jsView on unpkg · L1660Package source references dynamic require/import behavior.
dist/extensions/sycode-mcp-adapter/proxy-modes.jsView on unpkg · L19Package source executes code through a VM context API.
extensions/sycode-mcp-adapter/mcp-script-worker.mjsView on unpkg · L40A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/extensions/sycode-mcp-adapter/ui-session.jsView on unpkg · L83Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-mcp-adapter/ui-session.jsView on unpkgA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/src/cli.jsView on unpkg · L4Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/src/cloud.jsView on unpkg · L12Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cloud.jsView on unpkg