DANGER
malware detected
github.com / march4th8
march4th8/ reqcore
809 files·commit 63a2968·scanned 3d ago·cached ✓
100/100
MALICIOUS
Matches known-malicious patterns. Do not clone or install.
This repository contains patterns associated with malware. Do NOT run this code.
verdict accurate?
Created 8 days ago
No stars or forks
Created 8 days ago
No community activity
Partial architecture graph
threat-state: maliciouslive
FINDINGS ░▒▓
warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.shared/countries.json+4
warningHigh-entropy string literalsFound 5 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.server/utils/auth.ts+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.ee/server/api/ai-analysis/stats.get.ts+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.ee/server/api/webhooks/resend.post.ts+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.server/api/admin/retention/review.get.ts+3
warningHigh-entropy string literalsFound 14 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.server/api/feedback.post.ts+3
warningHigh-entropy string literalsFound 3 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.server/api/interviews/index.get.ts+3
infoSuspicious file in repoVery large source file (681KB) — could contain obfuscated payloadpackage-lock.json+2
infoSuspicious file in repoVery large source file (1448KB) — could contain obfuscated payloadserver/utils/geo/data/cities.json+2
warningPossible typosquat: nuxt"nuxt" is only 1 character(s) away from the popular package "next". This is a common supply-chain attack vector.package.json+4
warningDependency runs install scripts"<root>/postinstall" executes code during installation. Malicious packages use this to drop payloads before the app even runs.package.json+3
Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
517 files scanned @ 63a2968 | 8/21/2026 | heuristic scan — always review manually
risk by category
code execution2
network & exfiltration0
file system access0
obfuscation15
supply chain13
owasp / injection0
telemetry
files 517/809rules hit 13engine v5commit 63a2968
github
march4th8/reqcore
The open-source applicant tracking system
0
0
11d
809 files
517 scanned(64%)
63a2968
architecture░▒▓
entry (1) flagged (77) pkg (84)
484 nodes · 1066 edgesscroll to zoom · click node to jump to finding