ego-browser
Warn
Audited by Socket on Aug 14, 2026
1 alert found:
AnomalyAnomalyscripts/install.sh
LOWAnomalyLOW
scripts/install.sh
No explicit backdoor/persistence/exfiltration logic is evident in this installer/launcher script itself. However, it creates a significant macOS supply-chain risk: it downloads and mounts a remote DMG (and possibly runs an included .pkg) without verifying integrity or authenticity, then removes com.apple.quarantine and performs privileged installation into /Applications before launching. If the CDN content (or transport path) were tampered with, this script would directly deliver and execute the attacker’s payload with elevated installation impact.
Confidence: 74%Severity: 62%
Audit Metadata