syCode — terminal coding agent + team daemon sidecar for remote monitoring.
An extension loaded by the CLI sends compacted agent conversation transcripts to the vendor cloud automatically after agent completion. The behavior is enabled for logged-in users without a consent control.
Package source references child process execution.
dist/extensions/sycode-background/src/core/fusion/pi-child.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/fusion/pi-child.jsView on unpkgPackage source references shell execution.
dist/extensions/sycode-mcp-adapter/utils.jsView on unpkg · L108Package source references dynamic code evaluation.
dist/extensions/sycode-background/src/core/anthropic-attribution.jsView on unpkg · L1660Package source references dynamic require/import behavior.
dist/extensions/sycode-mcp-adapter/proxy-modes.jsView on unpkg · L19Package source executes code through a VM context API.
extensions/sycode-mcp-adapter/mcp-script-worker.mjsView on unpkg · L40A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/extensions/sycode-mcp-adapter/ui-session.jsView on unpkg · L83Source downloads or fetches remote code and executes it.
dist/src/cli.jsView on unpkg · L4A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/src/cli.jsView on unpkg · L4Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/src/cloud.jsView on unpkg · L12Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cloud.jsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/extensions/sycode-background/src/core/fusion/web-fetch.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/extensions/sycode-background/src/core/common.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/registry.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-mcp-adapter/mcp-auth.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-background/src/core/registry.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-mcp-adapter/mcp-auth.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-mcp-adapter/request-headers-command.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/daemon-manage.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-background/src/core/fusion/pi-child.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-mcp-adapter/request-headers-command.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/attested-pi-run.jsView on unpkgThis report applies to @synotech/code@1.5.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli.jsView on unpkgPackage source references child process execution.
dist/extensions/sycode-background/src/core/fusion/pi-child.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/fusion/pi-child.jsView on unpkgSource downloads or fetches remote code and executes it.
Source reaches cloud instance metadata or link-local credential endpoints.
dist/extensions/sycode-background/src/core/fusion/web-fetch.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/extensions/sycode-background/src/core/common.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/registry.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-mcp-adapter/mcp-auth.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-background/src/core/registry.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-mcp-adapter/mcp-auth.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-mcp-adapter/request-headers-command.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/daemon-manage.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-background/src/core/fusion/pi-child.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-mcp-adapter/request-headers-command.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/attested-pi-run.jsView on unpkgPackage source references shell execution.
dist/extensions/sycode-mcp-adapter/utils.jsView on unpkg · L108Package source references dynamic code evaluation.
dist/extensions/sycode-background/src/core/anthropic-attribution.jsView on unpkg · L1660Package source references dynamic require/import behavior.
dist/extensions/sycode-mcp-adapter/proxy-modes.jsView on unpkg · L19Package source executes code through a VM context API.
extensions/sycode-mcp-adapter/mcp-script-worker.mjsView on unpkg · L40A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/extensions/sycode-mcp-adapter/ui-session.jsView on unpkg · L83A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/src/cli.jsView on unpkg · L4Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/src/cloud.jsView on unpkg · L12Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cloud.jsView on unpkg