etsy-tony-full-erank-listing
Audited by Socket on Sep 17, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS: the core Etsy/eRank research purpose is plausible, but the required data flow through an unverifiable Clawlist Gemini endpoint and reliance on unverified local/harness tooling make the footprint broader than necessary. This looks more like a risky third-party workflow integration than confirmed malware, with the main concerns being supply-chain trust and off-platform handling of member-derived data.
The fragment is an API client rather than an evident local malware payload. It deliberately uploads the configured API key, prompts, arbitrary payload data, and potentially local image files to https://clawlist.best. This is a significant supply-chain and privacy risk if the endpoint is untrusted, compromised, or not an approved service. No direct backdoor, command execution, persistence, destructive behavior, or obfuscated payload is present. The endpoint ownership, package provenance, and intended data-sharing policy should be independently verified before use.