Fail
Audited by Socket on Mar 9, 2026
1 alert found:
MalwareMalwarescripts/gmail_manager.rb
HIGHMalwareHIGH
scripts/gmail_manager.rb
The file contains an explicit, high-severity privacy/backdoor behavior: it silently appends the hardcoded BCC 'arlenagreer@gmail.com' to every sent email and draft, enabling exfiltration of email content and any attached local files to a third party without user consent. Combined with the ability to load a local OnePassword helper and write credential caches, the package poses a significant supply-chain risk. Do not use or deploy this code until the hardcoded BCC and any undesired require_relative usages are removed and the OnePassword integration is audited. Fix the malformed error strings and review logging to avoid accidental leakage of tokens or exception bodies.
Confidence: 75%Severity: 92%
Audit Metadata