The shipped bytecode advertises a remote-controlled AI agent with shell, file, browser, download, and persistence capabilities. Its supplied launcher currently fails because its src utility import is absent, leaving the opaque payload inert in this package.
Static reason
No blocking static signals were detected.
Trigger
Explicit execution of vanexa-agent, if the missing launcher dependency is restored.
Impact
Could execute commands and modify files under user-authorized agent operation; no concrete malicious chain is confirmed.
Mechanism
Opaque bytecode agent accepts relayed tasks and exposes local execution tools.
Rationale
Warn because the opaque payload contains high-risk AI-agent capabilities and disables relevant scanner categories, while the readable launcher cannot execute as packaged. The evidence does not establish malware, exfiltration, or unconsented install-time control-surface mutation.
Evidence
package.jsonbin/vanexa-agent.jsdist/bundle.jscsocket.jsonsocket.ymlREADME.mdsrc/utils/cli_ui.js~/.vanexa
Network endpoints1
vanexa-agent-relay.workers.dev