// npm 패키지
carvus-lens
Circle-to-Search for desktop — draw a circle on your screen to instantly search Google Lens, get AI answers, and translate text. Powered by Tesseract OCR and Groq AI.
버전
2
메인테이너
1
라이선스
MIT
최초 publish
2026-05-16
publisher
aadil-fazal
tarball
364,873 B
AUTO-PUBLISHED·1개 버전 인덱싱됨·최근 publish: 2026-05-16
// exfil path
what is read → where it shipssteals
- ● AI API keys
- ○ clipboard
sends to
(no destination string extracted — payload may be dynamic / obfuscated)
evidence in excerpt
> const { execSync } = require('child_process');
> execSync(`"${electronPath}" "${appPath}"`, { stdio: 'inherit' });// offending code· @1.0.1· 2 files flagged
llm: benign · 0.85→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
- @1.0.1··AUTO-PUBLISHED·publisher: aadil-fazalheuristic 75/100static flags 3llm benign (0.85) via ollamanew-publisher:10dhas-source-repoosv-flagged:MAL-2026-4505reads-ai-api-keysclipboard-accesschild-process-spawn
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
// NHI intent1 target·mixed harvest patterns·gate: always - gh CLI token storegh-cli-hosts
const GROQ_API_KEY = "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"
Activation gate: fires on every run. Harvest style: mixed harvest patterns.
