3 critical findings match patterns used by malware hidden in repos, set to run when you open the folder, when you install dependencies and when you start it. Fake take-home tests and “review our code” lures are built this way.
Don't open it in VS Code, Cursor or any other editor or IDE. Don't run npm install, pip install or any other install in it. Don't start it or run its scripts or tests.
If you already did: from another device, change the passwords saved in your browser, revoke GitHub, npm and cloud tokens, and move any crypto to a new wallet.
If someone sent it to you, check who they are before you reply, and don't run anything else they send.
When you open the folder
VS Code, Cursor, JetBrains, rust-analyzer, dev containers, Vim, Emacs, direnv, mise
CriticalRuns without asking
Opening the folder runs a font file as a program (task “eslint-check”)
.vscode/tasks.json tells VS Code, Cursor and other VS Code-based editors to run this when you open the folder. Once you trust the folder, VS Code runs it right away if you've ever allowed automatic tasks; otherwise it asks once, and that answer covers every trusted folder. Cursor ships with Workspace Trust off, and researchers have shown it running such tasks as soon as a folder opens. It runs public/fonts/fa-brands-regular.woff2 (a font file, which should never run as a program), which matches malware patterns: runs code hidden in an HTTP error response; evaluates data downloaded from a server; uses a raw IP on a port BeaverTail and InvisibleFerret use. It is set up to stay out of sight: terminal output hidden (reveal: "silent"), command not echoed, terminal closes itself afterwards, terminal never gets focus.
package.json runs postinstall automatically when you run npm, pnpm, yarn or bun install in this folder, before you've run the app. It runs scripts/check-node.js, which matches malware patterns: uses a raw IP on a port BeaverTail and InvisibleFerret use; downloads a script and pipes it to a shell; talks to a raw IP address. npm install --ignore-scripts skips it.
jsonwebtokn isn't on npm and looks like a misspelling of jsonwebtoken
No package called jsonwebtokn is published on npm, and the name is very close to jsonwebtoken. Anyone could register jsonwebtokn, and installs of this project would then download whatever they publish. Check whether jsonwebtoken was meant.
The “start” script (server/server.js → server/routes/auth.js → server/config/db.js) is how a take-home or client project expects you to start it. It runs server/config/db.js, which matches malware patterns: evaluates the body of an HTTP response; downloads code and runs it; uses a raw IP on a port BeaverTail and InvisibleFerret use.
10 direct dependencies. Checked against npm (packages it removed as malware, install scripts, downloads) and OSV malware advisories on Oct 11, 2026, when this example was captured.
Show the list
axios^1.7.2
dotenv^16.4.5
ethers^6.13.1
express^4.19.2
jsonwebtokn^9.0.2not on npm, like jsonwebtoken
mongoose^8.4.1
react^18.3.1
react-dom^18.3.1
react-scripts5.0.1
concurrently^8.2.2dev
What this report can't tell you
PreClone reads files; it never runs them. Code that is downloaded later from somewhere else, compiled binaries and encrypted payloads can hide from a static read.