Before you clone a "logger" or "grabber" script — or any repo you don't fully trust yet — paste the URL or upload a .zip. This checks Python and JS/TS source for the pattern that actually matters: code that collects system info AND ships it out over the network in the same file.
The specific pattern this checks for — recon plus an outbound call, in the same file — is the signature that shows up right before someone's cookies or credentials end up on a Discord webhook.
Paste the repo URL into a scanner like this one, which checks Python and JS/TS source for the pattern typically found in infostealer or "logger" scripts: code that collects system or browser info AND sends it out over the network in the same file.
A file that both collects system/user information (hostname, browser cookies, environment variables) and makes an outbound network request in the same file — the core signature of malware that harvests data and phones it home, as opposed to either behavior alone which is often completely normal.
No — it's heuristic, not exhaustive. It won't catch everything, especially deliberately obfuscated code, and it can false-positive on legitimate diagnostics or analytics tools. Treat findings as "review this before you trust it," not an automatic verdict.
No. Every scan runs in a temporary directory that's deleted before the result comes back — nothing is saved to a server or local filesystem.
Only source code — .py/.js/.jsx/.mjs/.cjs/.ts/.tsx files. Compiled binaries, obfuscated bundles, or minified production JS are outside what this heuristic scan can meaningfully read.
Usually a few seconds for a small repo, longer for large ones — the scanner clones the repo temporarily, checks every matching source file, then deletes the copy.
Treat it as a reason to actually read the flagged file before running the code, not an automatic verdict. Open the specific lines it points to and judge for yourself whether the behavior is legitimate.