Free · Report-Only · Nothing Saved

Check a Repo for Infostealer Patterns

Before you clone a "logger" or "grabber" script — or any repo you don't fully trust yet — paste the URL or upload a .zip. This checks Python and JS/TS source for the pattern that actually matters: code that collects system info AND ships it out over the network in the same file.

Scan a Repo Now →
GitHub, GitLab, Bitbucket, Codeberg, sourcehut — or upload a .zip
What this saves you
Skip enterprise security-scanner pricing just to sanity-check a sketchy repo before you clone it.

What this actually is

  1. 1Paste a public repo URL, or upload a .zip if the code isn't hosted anywhere you can link to.
  2. 2The scanner flags individual suspicious primitives (hardcoded Telegram/Discord exfil endpoints, browser credential-store paths, keylogging APIs) plus the composite pattern that matters most: recon + an outbound call in the same file.
  3. 3You get a clear verdict and a severity breakdown — review flagged findings yourself rather than treating any single hit as proof.

Who this is for

The specific pattern this checks for — recon plus an outbound call, in the same file — is the signature that shows up right before someone's cookies or credentials end up on a Discord webhook.

  • Developers about to clone a random GitHub tool or "grabber" script from a forum post or Discord link
  • Security-conscious hobbyists vetting a script before running it with elevated permissions
  • Students downloading course-related code from an unfamiliar source
  • Open-source maintainers doing a quick sanity check on a pull request before merging
  • IT support staff triaging a suspicious script a user downloaded

Frequently asked questions

How do I check if a GitHub repo is safe before running it?

Paste the repo URL into a scanner like this one, which checks Python and JS/TS source for the pattern typically found in infostealer or "logger" scripts: code that collects system or browser info AND sends it out over the network in the same file.

What is an infostealer pattern in code?

A file that both collects system/user information (hostname, browser cookies, environment variables) and makes an outbound network request in the same file — the core signature of malware that harvests data and phones it home, as opposed to either behavior alone which is often completely normal.

Does the scanner catch everything?

No — it's heuristic, not exhaustive. It won't catch everything, especially deliberately obfuscated code, and it can false-positive on legitimate diagnostics or analytics tools. Treat findings as "review this before you trust it," not an automatic verdict.

Is my code or repo saved anywhere?

No. Every scan runs in a temporary directory that's deleted before the result comes back — nothing is saved to a server or local filesystem.

Does it scan compiled binaries or only source code?

Only source code — .py/.js/.jsx/.mjs/.cjs/.ts/.tsx files. Compiled binaries, obfuscated bundles, or minified production JS are outside what this heuristic scan can meaningfully read.

How long does a scan take?

Usually a few seconds for a small repo, longer for large ones — the scanner clones the repo temporarily, checks every matching source file, then deletes the copy.

What should I do if it finds something?

Treat it as a reason to actually read the flagged file before running the code, not an automatic verdict. Open the specific lines it points to and judge for yourself whether the behavior is legitimate.

Being straight about this: this is a heuristic pattern scanner, not a security audit or a guarantee of safety. It only checks source files (.py/.js/.jsx/.mjs/.cjs/.ts/.tsx) for known infostealer-style patterns — it won't catch everything, especially deliberately obfuscated code, and it can false-positive on legitimate diagnostics/analytics code. Only public GitHub, GitLab, Bitbucket, Codeberg, or sourcehut URLs are accepted (https:// only).