Objectives
hostile severity, 95% confident.
anti-static/obfuscation/code-metrics
One-line script that decodes and executes or writes a payload (hostile)
hostile severity, 95% confident.
command-and-control/channel/deaddrop
URL dead drop / indirection pattern
suspicious severity, 90% confident.
anti-analysis/vm-detect
Node VM vendor string set
suspicious severity, 95% confident.
anti-static/obfuscation/encoding
Encoded child_process module
suspicious severity, 100% confident.
anti-static/obfuscation/eval
Generic Function constructor usage
suspicious severity, 90% confident.
anti-static/obfuscation/name-mangling
Mathematical Unicode indicator glyphs
suspicious severity, 92% confident.
anti-static/obfuscation/string
Heavy script body hidden in comment
suspicious severity, 95% confident.
collection/clipboard
Accesses system clipboard via xclip
suspicious severity, 94% confident.
command-and-control/backdoor/tasking
JS execSync command call
suspicious severity, 94% confident.
command-and-control/dropper
Spawned Python executes stdin payload
suspicious severity, 90% confident.
command-and-control/dropper/execution
Platform-branched payload dropper
suspicious severity, 90% confident.
command-and-control/remote-command
WebSocket sends host environment context
suspicious severity, 94% confident.
credential-access/env/secrets
Filters process.env for secret values
suspicious severity, 94% confident.
evasion/hijack-execution-flow
Node hidden module inject
suspicious severity, 92% confident.
evasion/security-bypass
checkServerIdentity returns undefined/null
suspicious severity, 94% confident.
exfiltration/stealer/credential
Node AWS credential path
suspicious severity, 93% confident.
exfiltration/stealer/host-profile
TS collects process and env
suspicious severity, 94% confident.
supply-chain/recon-exfil
Collects CI runtime env context
Micro-behaviors
suspicious severity, 95% confident.
fs/path/sensitive
Cloud provider credential file paths
Metadata
suspicious severity, 95% confident.
package/fields
Package executes preinstall hook script
20 of 152 traits shown
Identity
| SHA-256 | 84cbcf2723b82a76b4f447eed013b66c8b5942951d64cc18e9b91d7b5db1364c |
|---|---|
| Canonical SHA-256 | 0009efe1311c980ba44176671584a736b9aaeb7a14b3e9c11b808cd6493d3e1f |
| Filename | pi-coding-agent-0.79.4-h5585027_0.conda |
| Package | pi-coding-agent |
| Version | 0.79.4 |
Origin
| Source | forager |
|---|---|
| Feed | anaconda.org |
| Ecosystem | python |
| Domain | anaconda.org |
| URL | https://conda.anaconda.org/conda-forge/linux-64/pi-coding-agent-0.79.4-h5585027_0.conda |
Timeline
| First seen | 15 Jun 2026 06:46 UTC |
|---|---|
| First analyzed | 15 Jun 2026 06:48 UTC |
| Last analyzed | 15 Jun 2026 06:48 UTC |
| Last updated | 15 Jun 2026 06:48 UTC |
Labeling
| Label | unknown |
|---|---|
| Label source | forager |
| Traits version | 061e3 |
Not seeing what you expected? Let us know