syCode — terminal coding agent + team daemon sidecar for remote monitoring.
Running the sycode CLI automatically activates a cloud extension. At the end of every logged-in agent turn, it transmits a compacted transcript with account credentials to the vendor cloud without a runtime opt-out.
Package source references child process execution.
dist/extensions/sycode-background/src/core/fusion/pi-child.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/fusion/pi-child.jsView on unpkgPackage source references shell execution.
dist/extensions/sycode-mcp-adapter/utils.jsView on unpkg · L108Package source references dynamic code evaluation.
dist/extensions/sycode-background/src/core/anthropic-attribution.jsView on unpkg · L1660Package source references dynamic require/import behavior.
dist/extensions/sycode-mcp-adapter/proxy-modes.jsView on unpkg · L19Package source executes code through a VM context API.
extensions/sycode-mcp-adapter/mcp-script-worker.mjsView on unpkg · L40A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/extensions/sycode-mcp-adapter/ui-session.jsView on unpkg · L83Source downloads or fetches remote code and executes it.
dist/src/cli.jsView on unpkg · L4A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/src/cli.jsView on unpkg · L4Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/src/cloud.jsView on unpkg · L12Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cloud.jsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
dist/extensions/sycode-background/src/core/fusion/web-fetch.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/extensions/sycode-background/src/core/common.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/registry.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-mcp-adapter/mcp-auth.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-background/src/core/registry.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-mcp-adapter/mcp-auth.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-mcp-adapter/request-headers-command.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/daemon-manage.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-background/src/core/fusion/pi-child.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-mcp-adapter/request-headers-command.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/attested-pi-run.jsView on unpkgThis report applies to @synotech/code@1.5.9.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli.jsView on unpkgPackage source references child process execution.
dist/extensions/sycode-background/src/core/fusion/pi-child.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/fusion/pi-child.jsView on unpkgSource downloads or fetches remote code and executes it.
Source reaches cloud instance metadata or link-local credential endpoints.
dist/extensions/sycode-background/src/core/fusion/web-fetch.jsView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/extensions/sycode-background/src/core/common.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/registry.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-mcp-adapter/mcp-auth.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-background/src/core/registry.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-mcp-adapter/mcp-auth.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-mcp-adapter/request-headers-command.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/daemon-manage.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-background/src/core/fusion/pi-child.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
extensions/sycode-mcp-adapter/request-headers-command.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/extensions/sycode-background/src/core/attested-pi-run.jsView on unpkgPackage source references shell execution.
dist/extensions/sycode-mcp-adapter/utils.jsView on unpkg · L108Package source references dynamic code evaluation.
dist/extensions/sycode-background/src/core/anthropic-attribution.jsView on unpkg · L1660Package source references dynamic require/import behavior.
dist/extensions/sycode-mcp-adapter/proxy-modes.jsView on unpkg · L19Package source executes code through a VM context API.
extensions/sycode-mcp-adapter/mcp-script-worker.mjsView on unpkg · L40A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/extensions/sycode-mcp-adapter/ui-session.jsView on unpkg · L83A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist/src/cli.jsView on unpkg · L4Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cli.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/src/cloud.jsView on unpkg · L12Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/src/cloud.jsView on unpkg