CiCy - AI-powered operating system browser
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Package source references child process execution.
scripts/sync-runtime-deps.cjsView on unpkg · L13Package source references dynamic code evaluation.
workers/render/src/App.jsxView on unpkg · L1522Package source references weak cryptographic algorithms.
tools/arm-fblogin.jsView on unpkg · L6A manifest entrypoint or package-local install chain reaches persistence behavior.
src/main.jsView on unpkg · L82Source writes installer persistence such as shell profile or service configuration.
src/main.jsView on unpkg · L82A single source file combines environment access, network access, and code or shell execution with blocking evidence.
src/sidecar/host-mihomo.jsView on unpkg · L20Source downloads or fetches remote code and executes it.
src/sidecar/host-mihomo.jsView on unpkg · L20Source combines credential-like environment material and outbound requests; review data flow before blocking.
scripts/r2.mjsView on unpkg · L17Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
scripts/r2.mjsView on unpkg · L24Source writes persistence or remote-access backdoor material.
src/sidecar/colima-docker.jsView on unpkg · L26A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/sidecar/wsl-docker.jsView on unpkg · L16Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sidecar/wsl-docker.jsView on unpkgA manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
bin/cicy-desktop#virtual:normalized:round1View on unpkg · L495Package source invokes a package manager install command at runtime.
bin/cicy-desktop#virtual:normalized:round1View on unpkg · L34Package ships non-JavaScript build or shell helper files.
bin/preinstall.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/app-updater.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/backends/local-teams.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/backends/sidecar-ipc.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/backends/window-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/cloud/cloud-client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/main-old.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sidecar/docker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/exec-tools.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/system-tools.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cicy-desktopView on unpkgThis report applies to cicy-desktop@2.1.361.
See version security history for other recorded verdicts.
Evidence last updated: .
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sidecar/host-mihomo.jsView on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/r2.mjsView on unpkg · L17A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/cicy-desktop#virtual:normalized:round1View on unpkgPackage source references child process execution.
scripts/sync-runtime-deps.cjsView on unpkg · L13Source writes persistence or remote-access backdoor material.
src/sidecar/colima-docker.jsView on unpkg · L26A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
src/sidecar/wsl-docker.jsView on unpkg · L16Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sidecar/wsl-docker.jsView on unpkgA manifest entrypoint or package-local install chain reaches command-output exfiltration behavior.
bin/cicy-desktop#virtual:normalized:round1View on unpkg · L495Package source invokes a package manager install command at runtime.
bin/cicy-desktop#virtual:normalized:round1View on unpkg · L34Package ships non-JavaScript build or shell helper files.
bin/preinstall.shView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/app-updater.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/backends/local-teams.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/backends/sidecar-ipc.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/backends/window-manager.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/cloud/cloud-client.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/main-old.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sidecar/docker.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/exec-tools.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/system-tools.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/cicy-desktopView on unpkgPackage source references dynamic code evaluation.
workers/render/src/App.jsxView on unpkg · L1522Package source references weak cryptographic algorithms.
tools/arm-fblogin.jsView on unpkg · L6Source writes installer persistence such as shell profile or service configuration.
src/main.jsView on unpkg · L82A manifest entrypoint or package-local install chain reaches persistence behavior.
src/main.jsView on unpkg · L82A single source file combines environment access, network access, and code or shell execution with blocking evidence.
src/sidecar/host-mihomo.jsView on unpkg · L20Source downloads or fetches remote code and executes it.
src/sidecar/host-mihomo.jsView on unpkg · L20Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/sidecar/host-mihomo.jsView on unpkgSource combines credential-like environment material and outbound requests; review data flow before blocking.
scripts/r2.mjsView on unpkg · L17Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
scripts/r2.mjsView on unpkg · L24Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
scripts/r2.mjsView on unpkg · L17A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
bin/cicy-desktop#virtual:normalized:round1View on unpkg