CiCy - AI-powered operating system browser
At runtime, the package fetches unsigned remote executables and can install them without a fresh user confirmation. It also establishes hidden persistence and grants a container SSH access to the host account.
Package source references child process execution.
scripts/sync-runtime-deps.cjsView on unpkg · L13Source combines credential-like environment material and outbound requests; review data flow before blocking.
scripts/r2.mjsView on unpkg · L17Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
scripts/r2.mjsView on unpkg · L24Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/r2.mjsView on unpkg · L17Package source references dynamic code evaluation.
workers/render/src/App.jsxView on unpkg · L1522Package source references weak cryptographic algorithms.
tools/arm-fblogin.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches persistence behavior.
src/main.jsView on unpkg · L74Source writes installer persistence such as shell profile or service configuration.
src/main.jsView on unpkg · L74A single source file combines environment access, network access, and code or shell execution with blocking evidence.
src/sidecar/host-mihomo.jsView on unpkg · L20Source downloads or fetches remote code and executes it.
src/sidecar/host-mihomo.jsView on unpkg · L20Source writes persistence or remote-access backdoor material.
src/sidecar/colima-docker.jsView on unpkg · L26A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/sidecar/wsl-docker.jsView on unpkg · L16A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
bin/cicy-desktop#virtual:normalized:round1View on unpkg · L495Package source invokes a package manager install command at runtime.
bin/cicy-desktop#virtual:normalized:round1View on unpkg · L34Package ships non-JavaScript build or shell helper files.
bin/preinstall.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/backends/homepage-react/assets/index-BWZkvmvO.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/app-updater.jsView on unpkgThis report applies to cicy-desktop@2.1.359.
See version security history for other recorded verdicts.
Evidence last updated: .
A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/cicy-desktop#virtual:normalized:round1View on unpkgPackage source references child process execution.
scripts/sync-runtime-deps.cjsView on unpkg · L13Source writes persistence or remote-access backdoor material.
src/sidecar/colima-docker.jsView on unpkg · L26A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/sidecar/wsl-docker.jsView on unpkg · L16A manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
bin/cicy-desktop#virtual:normalized:round1View on unpkg · L495Package source invokes a package manager install command at runtime.
bin/cicy-desktop#virtual:normalized:round1View on unpkg · L34Package ships non-JavaScript build or shell helper files.
bin/preinstall.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/backends/homepage-react/assets/index-BWZkvmvO.jsView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/app-updater.jsView on unpkgSource combines credential-like environment material and outbound requests; review data flow before blocking.
scripts/r2.mjsView on unpkg · L17Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
scripts/r2.mjsView on unpkg · L24Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/r2.mjsView on unpkg · L17Package source references dynamic code evaluation.
workers/render/src/App.jsxView on unpkg · L1522Package source references weak cryptographic algorithms.
tools/arm-fblogin.jsView on unpkg · L6Source writes installer persistence such as shell profile or service configuration.
src/main.jsView on unpkg · L74A manifest entrypoint or package-local install chain reaches persistence behavior.
src/main.jsView on unpkg · L74A single source file combines environment access, network access, and code or shell execution with blocking evidence.
src/sidecar/host-mihomo.jsView on unpkg · L20Source downloads or fetches remote code and executes it.
src/sidecar/host-mihomo.jsView on unpkg · L20A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/cicy-desktop#virtual:normalized:round1View on unpkg