github.com / nachitzaid
nachitzaid/ lando-noris
CSS·73 files·commit 3cfd921·scanned 2h ago·cached ✓
40/100
SUSPICIOUS
Obfuscation or dynamic code paths detected. Intent unclear — review before running anything.
verdict accurate?
threat-state: suspiciouslive
FINDINGS ░▒▓
warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.gl/basis/basis_transcoder.js+4
warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.gl/fonts/MonaSans-Bold-msdf.json+4
warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.js/lando-offbrand.main.js+4
infoMinified code in source directoryMinified/obfuscated code in source directories (not dist/) makes code review impossible.js/lando-offbrand.main.js+3
infoMinified code in source directoryMinified/obfuscated code in source directories (not dist/) makes code review impossible.js/lando-offbrand.schunk.js+3
warningHigh-entropy string literalsFound 4 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.gl/basis/basis_transcoder.js+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.gl/basis/basis_transcoder.js+3
warningHigh-entropy string literalsFound 6 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.js/lando-offbrand.schunk.js+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.js/lando-offbrand.schunk.js+3
warningHigh-entropy string literalsFound 42 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.js/transitions-rive-isolate.js+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.js/transitions-rive-isolate.js+3
infoSuspicious file in repoVery large source file (703KB) — could contain obfuscated payloadgl/draco/draco_decoder.js+2
infoSuspicious file in repoVery large source file (1423KB) — could contain obfuscated payloadjs/lando-by-OFF-BRAND.js+2
infoSuspicious file in repoVery large source file (1292KB) — could contain obfuscated payloadjs/lando.gold-v3.js+2
Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
10 files scanned @ 3cfd921 | 9/25/2026 | heuristic scan — always review manually
risk by category
code execution2
network & exfiltration0
file system access0
obfuscation15
supply chain11
owasp / injection0
telemetry
files 10/73rules hit 16engine v6commit 3cfd921
github
nachitzaid/lando-noris
10
0
133d
73 files
10 scanned(14%)
3cfd921
architecture░▒▓
entry (0) flagged (4) pkg (0)
5 nodes · 0 edgesscroll to zoom · click node to jump to finding