Jev in production › Code and security review

is-malicious (luantak)

CLI that sends a codebase's source, config, build and CI files to Jev and reports files and lines with probable data theft, hidden network activity or backdoors, exiting nonzero on high-severity findings.

Open on GitHub ↗

The source publishes no measured number.
Use
Code and security review
Industry
Security
Form
Open-source tool
Stage
In production
Listed
2026-09-20
Found via
github
Repository
luantak/is-malicious
Stars
37
Forks
4
Last push
2026-09-23
Language
TypeScript
License
MIT

The README opens with

Scan a codebase for hidden, deceptive, or data-stealing behavior with TypeSafe Jev. The CLI sends source, configuration, build, and CI files to Jev for review, then points you to suspicious files and lines.

Use it as a second opinion before running unfamiliar code. A clean report is not proof that a project is safe.

Omit the path to scan the current directory. Scans send file contents to the TypeSafe API and use paid input tokens. The report includes token usage and a calculated input cost.

Badge

For the project's own README, linking back here:

Listed in Jev in production

Also used for code and security review