Open-source atomic malware analysis

Analyze another

pi-coding-agent-0.79.4-h5585027_0.conda

CONDA
Verdict: SUSPICIOUS

Objectives

hostile severity, 95% confident.
anti-static/obfuscation/code-metrics One-line script that decodes and executes or writes a payload (hostile)
hostile severity, 95% confident.
command-and-control/channel/deaddrop URL dead drop / indirection pattern
suspicious severity, 90% confident.
anti-analysis/vm-detect Node VM vendor string set
suspicious severity, 95% confident.
anti-static/obfuscation/encoding Encoded child_process module
suspicious severity, 100% confident.
anti-static/obfuscation/eval Generic Function constructor usage
suspicious severity, 90% confident.
anti-static/obfuscation/name-mangling Mathematical Unicode indicator glyphs
suspicious severity, 92% confident.
anti-static/obfuscation/string Heavy script body hidden in comment
suspicious severity, 95% confident.
collection/clipboard Accesses system clipboard via xclip
suspicious severity, 94% confident.
command-and-control/backdoor/tasking JS execSync command call
suspicious severity, 94% confident.
command-and-control/dropper Spawned Python executes stdin payload
suspicious severity, 90% confident.
command-and-control/dropper/execution Platform-branched payload dropper
suspicious severity, 90% confident.
command-and-control/remote-command WebSocket sends host environment context
suspicious severity, 94% confident.
credential-access/env/secrets Filters process.env for secret values
suspicious severity, 94% confident.
evasion/hijack-execution-flow Node hidden module inject
suspicious severity, 92% confident.
evasion/security-bypass checkServerIdentity returns undefined/null
suspicious severity, 94% confident.
exfiltration/stealer/credential Node AWS credential path
suspicious severity, 93% confident.
exfiltration/stealer/host-profile TS collects process and env
suspicious severity, 94% confident.
supply-chain/recon-exfil Collects CI runtime env context

Micro-behaviors

suspicious severity, 95% confident.
fs/path/sensitive Cloud provider credential file paths

Metadata

suspicious severity, 95% confident.
package/fields Package executes preinstall hook script

20 of 152 traits shown

Identity

SHA-256 84cbcf2723b82a76b4f447eed013b66c8b5942951d64cc18e9b91d7b5db1364c
Canonical SHA-256 0009efe1311c980ba44176671584a736b9aaeb7a14b3e9c11b808cd6493d3e1f
Filename pi-coding-agent-0.79.4-h5585027_0.conda
Package pi-coding-agent
Version 0.79.4

Origin

Source forager
Feed anaconda.org
Ecosystem python
Domain anaconda.org
URL https://conda.anaconda.org/conda-forge/linux-64/pi-coding-agent-0.79.4-h5585027_0.conda

Timeline

First seen 15 Jun 2026 06:46 UTC
First analyzed 15 Jun 2026 06:48 UTC
Last analyzed 15 Jun 2026 06:48 UTC
Last updated 15 Jun 2026 06:48 UTC

Labeling

Label unknown
Label source forager
Traits version 061e3