No malicious package attack surface is confirmed. Runtime networking implements the advertised Bandcamp/Roon extension and local web relay.
Static reason
One or more suspicious static signals were detected.
Trigger
User starts the extension and uses its web UI/Roon integration.
Impact
Bandcamp cookie is retained in the configured local state file; the unauthenticated LAN API exposes playback/settings control.
Mechanism
Fetches Bandcamp content, relays audio, and stores user-provided local settings.
Rationale
The source matches its stated Bandcamp-to-Roon functionality and contains no install-time execution, exfiltration path, remote code execution, or stealth persistence. The LAN API and local credential storage are product-security considerations, not evidence of malicious intent.
Evidence
package.jsonsrc/index.tssrc/core/config.tssrc/core/logger.tssrc/bandcamp/client.tssrc/web/server.tsconfig/state.jsonconfig/roonstate.json
Network endpoints2
bandcamp.comf4.bcbits.com