0repositories scanned in the last week

35 rules · nothing is cloned or executed

Is this GitHub repo safe to clone?

Malware now hides in GitHub repositories: fake tools, cheats and job-interview projects that run code the moment you install, build or open them. GiTRay reads the repository the safe way and tells you what it found, line by line.

Try:

Recently scanned

See all →

What GiTRay looks for

All 35 rules →

Malicious dependencies

1

Packages in package.json, lockfiles and Python requirements that OSV lists as confirmed malware.

Runs automatically

10

npm install hooks, setup.py, VS Code tasks and settings, dev containers, AI assistant hooks, .npmrc, direnv, build events.

Malicious code patterns

8

Decode-and-execute, curl | sh, browser password and cookie theft, SSH keys, crypto wallets, Discord/Telegram exfiltration, Windows LOLBins.

Hidden or obfuscated content

4

Random-looking blobs, Trojan Source bidi characters, code pushed off-screen with whitespace, invisible Unicode payloads.

Download links

4

Executables and archives outside the repo's own releases, file-sharing sites, link shorteners, archive passwords.

Social engineering

1

README instructions to disable antivirus, add exclusions or ignore a "false positive".

Binary files

3

Committed PE/ELF/Mach-O executables, .lnk shortcuts, password-protected archives, files antivirus engines detect. Files inside ZIPs are unpacked in memory and scanned too.

Repository signals

3

Brand-new owner accounts, freshly created repositories, and files hidden from GitHub's download archive.

CI workflows

1

CI configurations that pipe downloads into a shell (they run on the build server, not your machine).

Verdicts

Clean
Score below 30

No known malware tricks were found. That is not a guarantee: GiTRay looks for known patterns and does not run the code.

Suspicious
Score 30 to 69

Some patterns that malware uses were found. Read the findings before you install, build or run anything from this repository.

Dangerous
Score 70 or more

Several strong signs of malware. Do not clone, install, build or open this repository in an IDE unless you understand every finding.

Incomplete
A limit stopped the scan

A safety limit stopped the scan before every file was read. The part that was read looks clean, but a partial scan is never called clean: the payload could be in the unread part.

GiTRay is a static scanner: it recognises known tricks, it does not run code in a sandbox. A clean result lowers the risk; it does not prove a repository is safe.