64OUT OF 100
CautionCautionSandbox run

PixelPlayerHQ/PixelPlayer

We ran PixelPlayerHQ/PixelPlayer, a unknown project, in an isolated sandbox. The project did not build to a runnable state. We observed no malicious behavior, credential access, or outbound exfiltration. Its score is held down by a new owner account.

Repository size
38491 KB
Packages
0
Stars
5528
Created
28 days ago
Reputation signals
PixelPlayerHQ avatar
PixelPlayerHQ
@PixelPlayerHQ
Account age28 days
Public repos2
Forks438
Community sentiment70

High engagement, but account age is a concern.

Code & behavior signals
New Organization Account
MediumReputation

The owner account 'PixelPlayerHQ' is only 28 days old, which is a common pattern for newly created or potentially hijacked accounts.

Metadata Inconsistency
LowReputation

The README links point to a different user ('theovilardo') than the current repository owner ('PixelPlayerHQ'), suggesting a potential transfer or fork history that should be verified.

What running it revealed
What it ran
Project typeunknown
Auto-buildDid not build
Ran to completionNo / crashed
Three agents read the code

Three agents — install-time, runtime, and payload — read the source in parallel and cross-verified. These are their inferences from reading the code; the runtime facts below are what actually happened when we ran it.

install agent flagged app/schemas/com.theveloper.pixelplay.data.database.PixelPlayDatabase/25.jsonCode read · not confirmed at runtime

Agent analysis (code read, not a runtime observation): This file is a **Room Database schema definition** (JSON format) for an Android application, specifically `PixelPlayDatabase`. ### Analysis * **Nature of the file:** This is a static configuration file generated by the Android Room persistence library. It defines the database structure (tables, columns, indices, and foreign keys) for version 25 of the app's database. * **Content:** The schema defines tables for music-related data: `songs`, `albums`, `artists`, `lyrics`, `favorites`, and integration-specific tables for `telegram_songs`, `netease_songs`, and `gdrive_songs`. * **Risk Assessment:** This file is **data, not code**. It does not contain executable logic, scripts, or obfuscated payloads. It is a declarative description of a SQL schema. There is no mechanism for this file to "run" or perform actions on a system. ### Conclusion There is no malicious behavior to observe in this file. It is a standard component of an Android application's data layer. **Detonation:** Not required. Detonating a static JSON schema file would yield no behavioral data, as it is not an executable or a script.

runtime agent flagged app/schemas/com.theveloper.pixelplay.data.database.PixelPlayDatabase/26.jsonCode read · not confirmed at runtime

Agent analysis (code read, not a runtime observation): This file is a Room database schema definition (JSON) for an Android application named `PixelPlay`. It describes the structure of various tables, including `songs`, `playlists`, `telegram_songs`, `netease_songs`, and `gdrive_songs`. ### Analysis * **Nature of File:** This is a static configuration file used by the Android Room persistence library to manage database migrations and schema validation. It is not executable code. * **Functionality:** It defines the schema for a music player application that appears to support local files, Telegram-based music, NetEase, and Google Drive integration. * **Suspicion Level:** Low. The file structure is standard for an Android project using Room. There are no signs of obfuscation, malicious SQL injection, or suspicious data exfiltration logic within this schema definition. ### Conclusion This file does not contain executable code and does not warrant detonation. It is a declarative schema definition. No malicious behavior was observed in this file.

payload agent flagged app/schemas/com.theveloper.pixelplay.data.database.PixelPlayDatabase/27.jsonCode read · not confirmed at runtime

Agent analysis (code read, not a runtime observation): This file is a Room database schema definition (`27.json`) for an Android application named `PixelPlay`. It describes the structure of various tables, including `songs`, `albums`, `artists`, `playlists`, and integration-specific tables like `telegram_songs`, `netease_songs`, and `gdrive_songs`. ### Analysis * **Nature of the file:** This is a static configuration file used by the Android Room persistence library to manage database migrations and schema validation. It is not executable code. * **Content:** The schema defines standard music player data structures. The presence of `telegram_songs` and `gdrive_songs` tables suggests the app integrates with Telegram and Google Drive to fetch or manage music files. * **Suspicion:** While the file itself is benign (it is just a JSON schema), the *intent* of the application using this schema should be verified by examining the code that interacts with these tables (e.g., how it handles Telegram chat IDs or Google Drive file IDs). ### Conclusion There is no malicious behavior to observe by "detonating" a JSON schema file, as it contains no logic. **Recommendation:** No detonation is required for this file. Instead, I will focus on identifying the source code that implements the logic for the `telegram_songs` and `gdrive_songs` features, as those are the likely areas where credential handling or data exfiltration could occur. I will proceed to explore the repository to find the corresponding DAO (Data Access Object) or repository classes.

Network intent — what it tried to reach

No outbound connection attempts were observed during this run.

In-VM behavior
0
High-value credential reads · from planted decoys
0
Processes spawned
0
Files dropped
0.00
CPU cores busy
Containment proof
No real packet reached its destination

A control probe confirmed the sandbox intercepts all egress (the microVM has no route to the real internet except the forge) and a direct UDP query was dropped (non-TCP egress contained). The detonation itself made no outbound connection attempts during this run.

External monitor saw the egress attempt
In-VM trace corroborated it
Per-package scoring
Final verdict

We ran it in the sandbox and observed no malicious behavior, credential access, or outbound exfiltration.

End-to-end logs
Clone
›Cloned repository PixelPlayerHQ/PixelPlayer at commit 8b91d99c54fac8769d741479485bea50cf788011
Static scan
›No malicious patterns, obfuscation, or hardcoded secrets detected.
Reputation
›Owner account is only 28 days old.
›Discrepancy found between repo owner and README links.
Read
›README content aligns with the stated purpose of an Android music player.
Sandbox run
›Detonated under the sinkhole; the project did not build to a runnable state.
Score
›Score computed from the sandbox run: 64/100 (runtime-primary, deterministic)
›+100 [code] runtime_observation: The sandbox run scored 100/100 from observed runtime behavior — the primary signal.
›-12 [reputation] new_owner: Owner account is new (28 days old); new accounts are over-represented in throwaway attacks.
›-24 [code] incomplete_run_ceiling: The repo did not both build and run cleanly in the sandbox; the score is capped at 64.
Auto-published at clauderabbit.in/PixelPlayerHQ/PixelPlayer · re-checked when the repo changes