live · scanning repos
Scanrepo
github.com
DANGER
malware detected
github.com / hirotomasato

hirotomasato/tempik

TypeScript·17 files·commit 36d05ed·scanned 2h ago·cached ✓
70/100
DANGEROUS
Sensitive capability combinations reachable from entry points. Do not run without review.

This repository contains patterns associated with malware. Do NOT run this code.

verdict accurate?
threat-state: dangerouslive

FINDINGS ░▒▓

criticalSuspicious code is reachable from an entry pointFlagged files are imported by the application's entry path: src/db/queries.ts. This means the suspicious code can execute when the app runs.+8
warningHigh-entropy string literalsFound 3 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.src/db/queries.ts+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.src/db/queries.ts+3

Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.

9 files scanned @ 36d05ed | 9/25/2026 | heuristic scan — always review manually

risk by category
code execution8
network & exfiltration0
file system access0
obfuscation6
supply chain0
owasp / injection0
telemetry
files 9/17rules hit 3engine v6commit 36d05ed

github

hirotomasato/tempik

Tempik is a self-hosted disposable email service that runs entirely on Cloudflare Workers

TypeScript
107
53
91d
17 files
9 scanned(53%)
36d05ed

architecture░▒▓

entry (1) flagged (1) pkg (3)
9 nodes · 10 edgesscroll to zoom · click node to jump to finding