No confirmed malicious attack surface was found. Risky primitives are consistent with a UiPath Python bridge that detects Python, forwards commands, manages UiPath auth, and records redacted telemetry.
Static reason
One or more suspicious static signals were detected.
Trigger
Runtime use of exported setup, exec, auth, or registered CLI helper functions by a consumer.
Impact
May read/write UiPath auth/cache files and send expected auth or telemetry requests; no evidence of unauthorized harvesting or exfiltration.
Mechanism
User-invoked UiPath auth refresh, Python/uipath process spawning, and cache/auth file updates
Rationale
Static source inspection confirms the scanner hits are package-aligned auth, telemetry, Python detection, and command forwarding behavior, not install-time execution or covert exfiltration. I found no concrete malicious behavior, persistence, destructive action, dependency confusion, or AI-agent control-surface mutation.
Evidence
package.jsondist/index.js~/.uipath/.auth~/.uipath/.uipath-python-cache.json.env
Network endpoints3
cloud.uipath.com/identity_/connect/tokenwesteurope-5.in.applicationinsights.azure.com/westeurope.livediagnostics.monitor.azure.com/