Introduction

The DeepSeek Harness (dsh) plugin runs with real filesystem and process access. Existing audit tools (such as dsh-security-audit) are usually good at detecting capabilities (for example, a plugin can access the filesystem or network), but explicitly avoid judging intent, stating that they are only “audit assistance” rather than “antivirus software.” dsh-malware-audit fills this specific gap: it scans the actual Abstract Syntax Trees (ASTs) of installed plugins to look for malicious intent patterns, rather than relying on signature databases or raw text matching.

Installation and Enablement

  1. Install the plugin using the official command.
    dsh plugin --profile <name> add dsh-malware-audit
  1. Add the plugin name to the dsh.profile.bundles list; otherwise, the plugin will not be activated. Reference configuration is as follows:
    {
      "dsh": {
        "profile": {
          "bundles": [
            "@deepseek-ai/dsh-base",
            "@deepseek-ai/dsh-web-app",
            "dsh-malware-audit"
          ]
        }
      }
    }
  1. Verify that the configuration takes effect by checking whether the malware-audit configuration item exists.
    dsh --profile <name> --dump-config

Core Features and Usage

Manual Scan

Enter /scan-plugins in any session. This command scans all installed plugins that declare dsh.bundle, prints a discovery summary, and saves the full report to the .dsh-malware-audit/scan-<timestamp>.txt file in the current directory.

Scheduled Scans

By default, scanning is read-only. To enable scheduled scanning, set scheduleMinutes in the configuration file.

scheduleMinutes: 60

Set a value greater than 0 to enable it. Note: values less than 5 are rejected.

Automatic Quarantine

Enable the automatic quarantine feature (autoQuarantine: true). When a scan finds a critical-severity issue, the plugin is automatically quarantined.

Detection Rules

The plugin uses heuristic rules for scanning and does not include a known malicious package signature database. It mainly detects the following patterns:

Rule Severity Detection
dynamic-eval critical eval(), new Function(), and vm.Script-related calls
decode-then-execute critical Base64 decoding followed by direct input to eval() or require()
fetch-and-execute critical child_process invoking external commands such as curl/wget
cross-plugin-write critical Writing files into another plugin’s node_modules directory
raw-ip-network warning Using raw IP addresses instead of domain names for network requests
env-exfil-shape warning Network request parameters referencing process.env
child-process-shell notice Any child_process call

Configuration Reference

Configure plugin behavior in cordis.patch.yml:

- insert:
    - id: malware-audit
      name: 'dsh-malware-audit'
      config:
        maxFiles: 400
        maxFileBytes: 262144
        ignoreRuleIds: []
        ignorePlugins: []
        scheduleMinutes: 0
        autoQuarantine: false
Field Default Value Description
maxFiles 400 Maximum number of files per plugin; if exceeded, scanning of that plugin stops
maxFileBytes 262144 Maximum file size limit (256 KiB); if exceeded, the file is skipped
ignoreRuleIds [] Skip detection for specific rules
ignorePlugins [] Skip scanning specific plugins
scheduleMinutes 0 Automatic scan interval; 0 means disabled
autoQuarantine false Automatically quarantine when a critical issue is found

Quarantine Mechanism and Recovery

Quarantine Behavior

When autoQuarantine: true and a critical issue is found, quarantinePlugin() performs the following:
1. Moves the plugin’s node_modules entry to .dsh-malware-audit/quarantine/<name>-<timestamp>/.
2. Removes the plugin name from the dsh.profile.bundles list in all local configuration files.

Quarantine takes effect at the next startup and does not immediately stop the currently running process.

Restoring a Plugin

Manual restoration is required after quarantine:
1. Move the directory from .dsh-malware-audit/quarantine/ back under the profile’s node_modules.
2. Re-add the plugin name to dsh.profile.bundles in the configuration.

Notes

  1. Resource Limits: Scanning is limited to the plugin’s own directory and excludes node_modules, .git, lib, dist, and build. The per-plugin resource budget is a maximum of 400 files or 256 KiB.
  2. File Types: Only .js/.ts source files are scanned; documentation files such as .md and .json are not scanned.
  3. Not Antivirus Software: It is based on heuristic rules and does not include a known malicious package signature database.
  4. Dependency Environment: Requires Node.js >= 22.
  5. False Positive Risk: Although it performs AST scanning, known false positives are still possible (for example, certain JSDoc comments). It is recommended to manually run several scans and verify before enabling automatic quarantine.

Summary

dsh-malware-audit provides a static code analysis perspective different from traditional antivirus software, specifically targeting malicious intent patterns. It does not replace a full code audit but serves as a security assistance tool to help identify potentially malicious behavior in plugins.