live · scanning repos
Scanrepo
github.com
DANGER
malware detected
github.com / khushicode1234

khushicode1234/Crypto-tracker

JavaScript·51 files·commit da86c32·scanned 9d ago·cached ✓
70/100
DANGEROUS
Sensitive capability combinations reachable from entry points. Do not run without review.

This repository contains patterns associated with malware. Do NOT run this code.

verdict accurate?
Created 8 days ago
No stars or forks
Created 8 days ago
No community activity
threat-state: dangerouslive

FINDINGS ░▒▓

criticalSuspicious code is reachable from an entry pointFlagged files are imported by the application's entry path: src/config/firebaseConfig.js. This means the suspicious code can execute when the app runs.+8
infoSuspicious file in repoVery large source file (738KB) — could contain obfuscated payloadpackage-lock.json+2
warningHardcoded secret/credentialAPI keys, passwords, or tokens hardcoded in source code. Should be in environment variables.src/config/firebaseConfig.js
const firebaseConfig = {
    apiKey: "AIzaSyCSy_ltMlTqcL0FZWjhopSfzxH-fFl93I0",
    authDomain: "coin-insight.firebaseapp.com",
    projectId: "coin-insight",
+3

Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.

22 files scanned @ da86c32 | 8/26/2026 | heuristic scan — always review manually

risk by category
code execution8
network & exfiltration0
file system access0
obfuscation0
supply chain2
owasp / injection3
telemetry
files 22/51rules hit 3engine v5commit da86c32

github

khushicode1234/Crypto-tracker

JavaScript
0
0
18d
51 files
22 scanned(43%)
da86c32

architecture░▒▓

entry (1) flagged (1) pkg (20)
40 nodes · 100 edgesscroll to zoom · click node to jump to finding