Skip to content

Security Report: kilocode-agent/kilocode-2.0 is a malicious impersonation repo#1

Open
kilo-code-bot[bot] wants to merge 1 commit intomainfrom
session/agent_0186f621-dfa1-47ba-957f-341aaf65989a
Open

Security Report: kilocode-agent/kilocode-2.0 is a malicious impersonation repo#1
kilo-code-bot[bot] wants to merge 1 commit intomainfrom
session/agent_0186f621-dfa1-47ba-957f-341aaf65989a

Conversation

@kilo-code-bot
Copy link
Copy Markdown

@kilo-code-bot kilo-code-bot bot commented Mar 30, 2026

Summary

  • Comprehensive security investigation of kilocode-agent/kilocode-2.0, a repository impersonating the legitimate Kilo Code project
  • Verdict: MALICIOUS — trojanized binary distribution disguised as "Kilocode 2.0"
  • Source code is stolen from the open-source OpenCode project and used as a decoy; the actual attack vector is a 89 MB opaque binary (Kilocode_2_x64.7z) distributed via GitHub Releases

Key Findings

  1. Trojan binary in GitHub Releases (93.6 MB, 6 downloads at time of analysis)
  2. Source code is 100% OpenCode — zero references to "Kilo Code" in any source file; purely decorative
  3. Fraudulent account (kilocode-agent) created same day as repo, zero followers, single repo
  4. SEO poisoning via targeted topics (kilocode, download-kilocode, install-kilocode, etc.)
  5. Sophisticated social engineering README with fabricated feature comparisons
  6. No package.json — source cannot be built, confirming it is a decoy
  7. No eval(), obfuscated strings, or data exfiltration in the decoy source code (as expected — the malware is in the binary)

Recommended Actions

  • Report repository and account to GitHub
  • Warn the Kilo Code community
  • Anyone who downloaded and executed the binary should treat their system as compromised

…shing repo

Detailed analysis confirms this is a malicious impersonation of Kilo Code
distributing a trojan binary via GitHub Releases. Source code is stolen from
the OpenCode project and used purely as a decoy.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants