live · scanning repos
Scanrepo
github.com
DANGER
malware detected
github.com / andrraa

andrraa/pi-antigravity

TypeScript·27 files·commit 989bb2c·scanned 2h ago·cached ✓
70/100
DANGEROUS
Sensitive capability combinations reachable from entry points. Do not run without review.

This repository contains patterns associated with malware. Do NOT run this code.

verdict accurate?
Research / educational context
threat-state: dangerouslive

FINDINGS ░▒▓

criticalSuspicious code is reachable from an entry pointFlagged files are imported by the application's entry path: src/account/index.ts, src/auth/oauth.ts, src/client/client.ts. This means the suspicious code can execute when the app runs.+8
warningCluster of suspicious files reachable from entry7 flagged files form a connected cluster that is reachable from an entry point, suggesting coordinated malicious behavior rather than isolated false positives.+5
warningHigh-entropy string literalsFound 7 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.src/account/index.ts+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.src/account/index.ts+3
warningHigh-entropy string literalsFound 7 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.src/auth/oauth.ts+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.src/client/client.ts+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.src/models/models.ts+3
warningHigh-entropy string literalsFound 5 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.src/stream/stream.ts+3

Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.

24 files scanned @ 989bb2c | 9/25/2026 | heuristic scan — always review manually

risk by category
code execution13
network & exfiltration0
file system access0
obfuscation15
supply chain0
owasp / injection0
telemetry
files 24/27rules hit 8engine v6commit 989bb2c

github

andrraa/pi-antigravity

Multi-account Antigravity & Google Cloud Code provider extension for Pi Coding Agent.

TypeScript
2
0
33d
27 files
24 scanned(89%)
989bb2c

architecture░▒▓

entry (1) flagged (7) pkg (4)
25 nodes · 62 edgesscroll to zoom · click node to jump to finding
⚠️ DANGEROUS (70/100) — andrraa/pi-antigravity — ScanRepo