ego-browser

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/install.sh

No explicit malware behaviors (e.g., exfiltration, backdoors, or covert command execution) are evident in this shell script. However, it carries a meaningful supply-chain risk typical of remote installer scripts: it downloads and mounts a hardcoded remote DMG without any integrity/signature/notarization verification, then removes com.apple.quarantine and launches/installs the resulting application with elevated install privileges when required. If the CDN content/transport integrity is compromised, this script would likely install and run the attacker’s payload.

Confidence: 70%Severity: 65%
Audit Metadata
Analyzed At
Aug 11, 2026, 01:21 AM
Package URL
pkg:socket/skills-sh/citrolabs%2Fego-lite%2Fego-browser%2F@506a6c0282fb9879be72971ab6c418b76b41589d33ad2c0d3b2cc2965192f58c
Security Audit — socket — ego-browser