CiCy - AI-powered operating system browser
Static analysis completed at 0.0% confidence. No malicious behavior was detected; 35 low-signal pattern(s) were surfaced and cleared.
Package source references child process execution.
scripts/sync-runtime-deps.cjsView on unpkg · L13Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cicy-desktopView on unpkgPackage source references weak cryptographic algorithms.
src/tools/file-tools.jsView on unpkg · L8Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sidecar/docker.jsView on unpkgSource writes installer persistence such as shell profile or service configuration.
src/sidecar/docker.jsView on unpkg · L10A single source file combines environment access, network access, and code or shell execution with blocking evidence.
src/sidecar/host-mihomo.jsView on unpkg · L20Source downloads or fetches remote code and executes it.
src/sidecar/host-mihomo.jsView on unpkg · L20Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
bin/cicy-desktop#virtual:normalized:round1View on unpkg · L494A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
bin/cicy-desktop#virtual:normalized:round1View on unpkg · L494A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/cicy-desktop#virtual:normalized:round1View on unpkgSource writes persistence or remote-access backdoor material.
src/sidecar/colima-docker.jsView on unpkg · L26Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/tools/system-tools.jsView on unpkg · L4Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/system-tools.jsView on unpkgA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/sidecar/wsl-docker.jsView on unpkg · L16A manifest entrypoint or package-local install chain reaches persistence behavior.
src/sidecar/wsl-docker.jsView on unpkg · L16Package source invokes a package manager install command at runtime.
scripts/build-homepage.cjsView on unpkg · L27Package ships non-JavaScript build or shell helper files.
bin/preinstall.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/backends/local-teams.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/backends/window-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/cloud/cloud-client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/main-old.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/exec-tools.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/backends/ipc.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sidecar/localbin.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sidecar/runtime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tabbrowser/redroid-matrix.jsView on unpkgThis report applies to cicy-desktop@2.1.305.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references child process execution.
scripts/sync-runtime-deps.cjsView on unpkg · L13Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
bin/cicy-desktop#virtual:normalized:round1View on unpkg · L494A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
bin/cicy-desktop#virtual:normalized:round1View on unpkg · L494Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
src/tools/system-tools.jsView on unpkg · L4Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/system-tools.jsView on unpkgA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/sidecar/wsl-docker.jsView on unpkg · L16A manifest entrypoint or package-local install chain reaches persistence behavior.
src/sidecar/wsl-docker.jsPackage source invokes a package manager install command at runtime.
scripts/build-homepage.cjsView on unpkg · L27Package ships non-JavaScript build or shell helper files.
bin/preinstall.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/backends/local-teams.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/backends/window-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/cloud/cloud-client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/main-old.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/exec-tools.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/backends/ipc.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sidecar/localbin.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sidecar/runtime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tabbrowser/redroid-matrix.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cicy-desktopView on unpkgPackage source references weak cryptographic algorithms.
src/tools/file-tools.jsView on unpkg · L8Source writes installer persistence such as shell profile or service configuration.
src/sidecar/docker.jsView on unpkg · L10Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sidecar/docker.jsView on unpkgA single source file combines environment access, network access, and code or shell execution with blocking evidence.
src/sidecar/host-mihomo.jsView on unpkg · L20Source downloads or fetches remote code and executes it.
src/sidecar/host-mihomo.jsView on unpkg · L20A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/cicy-desktop#virtual:normalized:round1View on unpkgSource writes persistence or remote-access backdoor material.
src/sidecar/colima-docker.jsView on unpkg · L26