Flagrix — Scan GitHub Repos Before You Clone
1 rating
)Overview
Scan GitHub repos and profiles for malware, backdoors, and supply-chain attacks — locally, before you clone. Free, no account.
Don't clone that repo yet. Fake recruiters send developers "coding assignments" that are actually malware. One npm install on a poisoned repository can steal your crypto wallets, SSH keys, and browser sessions. Flagrix scans GitHub repositories and profiles for these threats — entirely in your browser, before any damage is done. TRY IT IN 30 SECONDS Install Flagrix, open github.com/flagrix-io/flagrix-test-high — a test repo that contains no functional malicious code, only intentionally suspicious patterns — and click "Scan with Flagrix." You'll get a High Risk verdict with a score breakdown and every flagged file and pattern explained. WHAT IT DETECTS - Known malicious npm packages from active campaigns (e.g. BeaverTail) and typosquatted package names - Obfuscated code — hex arrays, eval chains, base64 payload droppers - Supply-chain risks — malicious dependencies and install-time scripts (postinstall hooks, curl-pipe-bash) - Backdoors, reverse shells, and hardcoded suspicious network calls - Data exfiltration — credential, session-token, and wallet-key harvesting; keylogger patterns - Crypto miners - Plus YARA-style matching of every scanned file against a curated, open-source signature database, updated as new campaigns are discovered Every finding shows the affected file, the suspicious pattern, and a plain-English explanation, with a score breakdown of exactly what was deducted and why — so you can verify the verdict yourself. VET THE "RECRUITER" TOO Scan any GitHub profile or organization: account age, repository authenticity, fork-only histories, and other signals of throwaway scam accounts. PRIVATE BY DESIGN — FULLY LOCAL - All scanning happens in your browser. Flagrix has no backend and collects nothing. - No account, no tracking, no analytics, no data sold — ever. - Your GitHub token (optional, for private repos) is stored locally and sent only to GitHub. - The only network calls are directly from your browser to the GitHub and npm APIs. - Detection rules are open source (MIT): github.com/flagrix-io/flagrix-detection-rules - Core scanning engine is open source (MIT): github.com/flagrix-io/flagrix-scanner-core FREE Flagrix is free with unlimited scans. It was built after real fake-recruiter campaigns cost developers real money. Signature updates ship as new campaigns are discovered. HOW IT WORKS 1. Install Flagrix 2. Visit any GitHub repository or profile 3. Click "Scan with Flagrix" 4. Review the risk assessment before you clone or run anything Risk assessments are informational, not definitive fraud determinations. No tool can guarantee a repository is 100% safe. Always verify through official channels.
5 out of 51 rating
Details
- Version0.5.1
- UpdatedJuly 16, 2026
- Offered byFlagrix
- Size244KiB
- LanguagesEnglish (United States)
- Developer
Email
support@flagrix.io - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, please open this page on your desktop browser