task-banner
Fail
Audited by Socket on Jul 17, 2026
1 alert found:
MalwareMalwaremac-overlay.js
HIGHMalwareHIGH
mac-overlay.js
This module contains multiple high-risk command execution primitives on macOS: it runs arbitrary shell commands via /bin/bash -lc using an environment-provided PEON_CLICK_COMMAND, and it executes external helper binaries using PEON_CMUX_* environment variables. Additionally, it constructs an osascript -e payload by concatenating attacker-influenced sessionTty into executed JavaScript code, enabling code injection into the automation script. These behaviors are strong indicators of potential sabotage/backdoor functionality when the corresponding inputs/env vars are set.
Confidence: 86%Severity: 90%
Audit Metadata