Malware scanner for unitypackage files
-
@GoatonicReal looking at that report, the file looks clean, just a lot of advices but nothing bad
@SummerTYT ahh oki i see,so its fine just be careful basically?
-
I've already updated the program; there are now fewer false positives compared to version 10 of poiyomi. I've also added a command to export a ".unitypackage" as a folder/zip file.
I also fixed the problem where the version wasn't displayed correctly when using the program (thanks @anonberry).
https://github.com/vicentefelipechile/vrchat-scanner/releases
Those who know how to use the terminal can extract the Unity packages; I will include an interface for this soon.

-
@SummerTYT ahh oki i see,so its fine just be careful basically?
@GoatonicReal Usually when is only "Low" flags, then is safe
-
ahhh oki i getcha, thank you for the updated version ^^
was wondering why it was showing "0.4" -
also for that file, should i just stay clear of it? or (just a lil dumb)
-
also for that file, should i just stay clear of it? or (just a lil dumb)
@GoatonicReal That unitypackage you have it should be safe to use
-
the latest poiyomi pro I got showed high risk, I don't know if I can use it:
======================================================================
vrcstorage-scanner — Batch Scan Report
Generated: Sat, 2 May 2026 16:23:51 +0000
Files scanned: 1SUMMARY
Score Risk Level Sanitize File
167 CRITICAL no Poi.Pro.10.0.9.unitypackage
======================================================================
FILE 1/1: D:\VR\Poi.Pro.10.0.9.unitypackageSHA-256 : 3e8b7520ae56fe3bff59ba165ac916809641cec49a9db1086777c4f44fc37678
Size : 100.9 MB
Score : 167 | Risk: CRITICAL | Duration: 1.11s | Action: AutoReject
Assets : total=1519 scripts=227 dlls=0 textures=284 audio=0 prefabs=9FINDINGS (15):
[HIGH + 40pt] File write/delete operations detected in C# script (CS_FILE_WRITE)
File: Assets/_PoiyomiShaders/Scripts/poi-tools/Editor/PoiTexturePacker/PoiTexturePacker.cs
Lines: 436, 457, 465[HIGH + 40pt] File write/delete operations detected in C# script (CS_FILE_WRITE)
File: Assets/_PoiyomiShaders/Scripts/Editor/ModularShaderSystem/LocalPreferences/ModuleTogglePreferences.cs
Lines: 233[HIGH + 40pt] File write/delete operations detected in C# script (CS_FILE_WRITE)
File: Assets/_PoiyomiShaders/Scripts/poi-tools/Editor/ModularShaderStuff/ModularShadersGeneratorWindow.cs
Lines: 489, 529[MEDIUM + 8pt] Texture file has high entropy 7.58 (possible embedded payload) (TEXTURE_HIGH_ENTROPY)
File: Assets/_PoiyomiShaders/Textures/Noise/T_Noise_No (9).TGA
Context: entropy=7.5828[MEDIUM + 8pt] Texture file has high entropy 7.96 (possible embedded payload) (TEXTURE_HIGH_ENTROPY)
File: Assets/_PoiyomiShaders/Prefabs/Glass.png
Context: entropy=7.9608[MEDIUM + 8pt] Texture file has high entropy 7.93 (possible embedded payload) (TEXTURE_HIGH_ENTROPY)
File: Assets/_PoiyomiShaders/Textures/Pixels/T_Pixel_IPS.png
Context: entropy=7.9337[MEDIUM + 4pt] Meta file contains external object references (assets not included in package) (META_EXTERNAL_REF)
File: Assets/_PoiyomiShaders/TPS/Assets/Carrot/carrot.fbx[MEDIUM + 4pt] Meta file contains external object references (assets not included in package) (META_EXTERNAL_REF)
File: Assets/_PoiyomiShaders/TPS/Assets/orifice.fbx[MEDIUM + 4pt] Meta file contains external object references (assets not included in package) (META_EXTERNAL_REF)
File: Assets/_PoiyomiShaders/TPS/Assets/Jar/Jar.fbx[MEDIUM + 4pt] Meta file contains external object references (assets not included in package) (META_EXTERNAL_REF)
File: Assets/_PoiyomiShaders/TPS/Assets/PenFBX.fbx[LOW + 2pt] File is a valid image but in a different format than its extension suggests (MAGIC_MISMATCH_IMAGE)
File: Assets/_PoiyomiShaders/Prefabs/Glass.png
Context: declared_ext=png[LOW + 2pt] File is a valid image but in a different format than its extension suggests (MAGIC_MISMATCH_IMAGE)
File: Assets/_PoiyomiShaders/Textures/Pixels/T_Pixel_IPS.png
Context: declared_ext=png[LOW + 1pt] Long Base64-encoded field in YAML prefab/asset (may be inline texture or payload) (PREFAB_INLINE_B64)
File: Assets/_PoiyomiShaders/Textures/Gifs/T_FireWorks_GIF.asset
Context: length=678032[LOW + 1pt] Long Base64-encoded field in YAML prefab/asset (may be inline texture or payload) (PREFAB_INLINE_B64)
File: Assets/_PoiyomiShaders/Textures/Gifs/T_Matrix_GIF.asset
Context: length=678032[LOW + 1pt] Long Base64-encoded field in YAML prefab/asset (may be inline texture or payload) (PREFAB_INLINE_B64)
File: Assets/_PoiyomiShaders/Textures/Gifs/T_2ColorLines_GIF.asset
Context: length=87808VERDICT: DO NOT INSTALL — potentially malicious, may compromise your system.
======================================================================
OVERALL RESULTSClean : 0
Low : 0
Medium : 0
High : 0
Critical : 1
Sanitized: 0vrcstorage-scanner by SummerTYT
-
the latest poiyomi pro I got showed high risk, I don't know if I can use it:
======================================================================
vrcstorage-scanner — Batch Scan Report
Generated: Sat, 2 May 2026 16:23:51 +0000
Files scanned: 1SUMMARY
Score Risk Level Sanitize File
167 CRITICAL no Poi.Pro.10.0.9.unitypackage
======================================================================
FILE 1/1: D:\VR\Poi.Pro.10.0.9.unitypackageSHA-256 : 3e8b7520ae56fe3bff59ba165ac916809641cec49a9db1086777c4f44fc37678
Size : 100.9 MB
Score : 167 | Risk: CRITICAL | Duration: 1.11s | Action: AutoReject
Assets : total=1519 scripts=227 dlls=0 textures=284 audio=0 prefabs=9FINDINGS (15):
[HIGH + 40pt] File write/delete operations detected in C# script (CS_FILE_WRITE)
File: Assets/_PoiyomiShaders/Scripts/poi-tools/Editor/PoiTexturePacker/PoiTexturePacker.cs
Lines: 436, 457, 465[HIGH + 40pt] File write/delete operations detected in C# script (CS_FILE_WRITE)
File: Assets/_PoiyomiShaders/Scripts/Editor/ModularShaderSystem/LocalPreferences/ModuleTogglePreferences.cs
Lines: 233[HIGH + 40pt] File write/delete operations detected in C# script (CS_FILE_WRITE)
File: Assets/_PoiyomiShaders/Scripts/poi-tools/Editor/ModularShaderStuff/ModularShadersGeneratorWindow.cs
Lines: 489, 529[MEDIUM + 8pt] Texture file has high entropy 7.58 (possible embedded payload) (TEXTURE_HIGH_ENTROPY)
File: Assets/_PoiyomiShaders/Textures/Noise/T_Noise_No (9).TGA
Context: entropy=7.5828[MEDIUM + 8pt] Texture file has high entropy 7.96 (possible embedded payload) (TEXTURE_HIGH_ENTROPY)
File: Assets/_PoiyomiShaders/Prefabs/Glass.png
Context: entropy=7.9608[MEDIUM + 8pt] Texture file has high entropy 7.93 (possible embedded payload) (TEXTURE_HIGH_ENTROPY)
File: Assets/_PoiyomiShaders/Textures/Pixels/T_Pixel_IPS.png
Context: entropy=7.9337[MEDIUM + 4pt] Meta file contains external object references (assets not included in package) (META_EXTERNAL_REF)
File: Assets/_PoiyomiShaders/TPS/Assets/Carrot/carrot.fbx[MEDIUM + 4pt] Meta file contains external object references (assets not included in package) (META_EXTERNAL_REF)
File: Assets/_PoiyomiShaders/TPS/Assets/orifice.fbx[MEDIUM + 4pt] Meta file contains external object references (assets not included in package) (META_EXTERNAL_REF)
File: Assets/_PoiyomiShaders/TPS/Assets/Jar/Jar.fbx[MEDIUM + 4pt] Meta file contains external object references (assets not included in package) (META_EXTERNAL_REF)
File: Assets/_PoiyomiShaders/TPS/Assets/PenFBX.fbx[LOW + 2pt] File is a valid image but in a different format than its extension suggests (MAGIC_MISMATCH_IMAGE)
File: Assets/_PoiyomiShaders/Prefabs/Glass.png
Context: declared_ext=png[LOW + 2pt] File is a valid image but in a different format than its extension suggests (MAGIC_MISMATCH_IMAGE)
File: Assets/_PoiyomiShaders/Textures/Pixels/T_Pixel_IPS.png
Context: declared_ext=png[LOW + 1pt] Long Base64-encoded field in YAML prefab/asset (may be inline texture or payload) (PREFAB_INLINE_B64)
File: Assets/_PoiyomiShaders/Textures/Gifs/T_FireWorks_GIF.asset
Context: length=678032[LOW + 1pt] Long Base64-encoded field in YAML prefab/asset (may be inline texture or payload) (PREFAB_INLINE_B64)
File: Assets/_PoiyomiShaders/Textures/Gifs/T_Matrix_GIF.asset
Context: length=678032[LOW + 1pt] Long Base64-encoded field in YAML prefab/asset (may be inline texture or payload) (PREFAB_INLINE_B64)
File: Assets/_PoiyomiShaders/Textures/Gifs/T_2ColorLines_GIF.asset
Context: length=87808VERDICT: DO NOT INSTALL — potentially malicious, may compromise your system.
======================================================================
OVERALL RESULTSClean : 0
Low : 0
Medium : 0
High : 0
Critical : 1
Sanitized: 0vrcstorage-scanner by SummerTYT
@ManMachine Poiyomi models are known for having a high number of scripts, it's more likely to be a false positive than being malware. The scanner should be updated in a near future to improve detection in poiyomi models.
-
the latest poiyomi pro I got showed high risk, I don't know if I can use it:
======================================================================
vrcstorage-scanner — Batch Scan Report
Generated: Sat, 2 May 2026 16:23:51 +0000
Files scanned: 1SUMMARY
Score Risk Level Sanitize File
167 CRITICAL no Poi.Pro.10.0.9.unitypackage
======================================================================
FILE 1/1: D:\VR\Poi.Pro.10.0.9.unitypackageSHA-256 : 3e8b7520ae56fe3bff59ba165ac916809641cec49a9db1086777c4f44fc37678
Size : 100.9 MB
Score : 167 | Risk: CRITICAL | Duration: 1.11s | Action: AutoReject
Assets : total=1519 scripts=227 dlls=0 textures=284 audio=0 prefabs=9FINDINGS (15):
[HIGH + 40pt] File write/delete operations detected in C# script (CS_FILE_WRITE)
File: Assets/_PoiyomiShaders/Scripts/poi-tools/Editor/PoiTexturePacker/PoiTexturePacker.cs
Lines: 436, 457, 465[HIGH + 40pt] File write/delete operations detected in C# script (CS_FILE_WRITE)
File: Assets/_PoiyomiShaders/Scripts/Editor/ModularShaderSystem/LocalPreferences/ModuleTogglePreferences.cs
Lines: 233[HIGH + 40pt] File write/delete operations detected in C# script (CS_FILE_WRITE)
File: Assets/_PoiyomiShaders/Scripts/poi-tools/Editor/ModularShaderStuff/ModularShadersGeneratorWindow.cs
Lines: 489, 529[MEDIUM + 8pt] Texture file has high entropy 7.58 (possible embedded payload) (TEXTURE_HIGH_ENTROPY)
File: Assets/_PoiyomiShaders/Textures/Noise/T_Noise_No (9).TGA
Context: entropy=7.5828[MEDIUM + 8pt] Texture file has high entropy 7.96 (possible embedded payload) (TEXTURE_HIGH_ENTROPY)
File: Assets/_PoiyomiShaders/Prefabs/Glass.png
Context: entropy=7.9608[MEDIUM + 8pt] Texture file has high entropy 7.93 (possible embedded payload) (TEXTURE_HIGH_ENTROPY)
File: Assets/_PoiyomiShaders/Textures/Pixels/T_Pixel_IPS.png
Context: entropy=7.9337[MEDIUM + 4pt] Meta file contains external object references (assets not included in package) (META_EXTERNAL_REF)
File: Assets/_PoiyomiShaders/TPS/Assets/Carrot/carrot.fbx[MEDIUM + 4pt] Meta file contains external object references (assets not included in package) (META_EXTERNAL_REF)
File: Assets/_PoiyomiShaders/TPS/Assets/orifice.fbx[MEDIUM + 4pt] Meta file contains external object references (assets not included in package) (META_EXTERNAL_REF)
File: Assets/_PoiyomiShaders/TPS/Assets/Jar/Jar.fbx[MEDIUM + 4pt] Meta file contains external object references (assets not included in package) (META_EXTERNAL_REF)
File: Assets/_PoiyomiShaders/TPS/Assets/PenFBX.fbx[LOW + 2pt] File is a valid image but in a different format than its extension suggests (MAGIC_MISMATCH_IMAGE)
File: Assets/_PoiyomiShaders/Prefabs/Glass.png
Context: declared_ext=png[LOW + 2pt] File is a valid image but in a different format than its extension suggests (MAGIC_MISMATCH_IMAGE)
File: Assets/_PoiyomiShaders/Textures/Pixels/T_Pixel_IPS.png
Context: declared_ext=png[LOW + 1pt] Long Base64-encoded field in YAML prefab/asset (may be inline texture or payload) (PREFAB_INLINE_B64)
File: Assets/_PoiyomiShaders/Textures/Gifs/T_FireWorks_GIF.asset
Context: length=678032[LOW + 1pt] Long Base64-encoded field in YAML prefab/asset (may be inline texture or payload) (PREFAB_INLINE_B64)
File: Assets/_PoiyomiShaders/Textures/Gifs/T_Matrix_GIF.asset
Context: length=678032[LOW + 1pt] Long Base64-encoded field in YAML prefab/asset (may be inline texture or payload) (PREFAB_INLINE_B64)
File: Assets/_PoiyomiShaders/Textures/Gifs/T_2ColorLines_GIF.asset
Context: length=87808VERDICT: DO NOT INSTALL — potentially malicious, may compromise your system.
======================================================================
OVERALL RESULTSClean : 0
Low : 0
Medium : 0
High : 0
Critical : 1
Sanitized: 0vrcstorage-scanner by SummerTYT
@ManMachine As @anonberry said, it's more likely to be a false positive, in the latest poiyomi version (v10) they implement more stuff that isn't the version 9 so I have to update
-
perfect, ty. I can use them without worry, then
-
This is very interesting, tried it on a few things myself, there were a couple that flagged, one being "high" the other being critical. How can you tell between a false positive and a real critical? And say there was something that flagged a false positive and you went ahead and cleaned it anyways, would that remove any vital things from the package and possibly break it? Just curious.
-
This is very interesting, tried it on a few things myself, there were a couple that flagged, one being "high" the other being critical. How can you tell between a false positive and a real critical? And say there was something that flagged a false positive and you went ahead and cleaned it anyways, would that remove any vital things from the package and possibly break it? Just curious.
@NewbKid Good question tho.
For the scanner, I try to avoid generic statements like "it has a .png extension, therefore it's a PNG." The scanner checks and verifies that things like images are what they claim to be. It also analyzes lines of code looking for potential unwanted behavior, such as file writing or Assembly code.
We're still working on the sanitization feature; it's difficult when you don't have a malicious .unitypackage file, haha. But for some files, the sanitizer deletes them. For scripts, it comments them out. That way, if there's any unusual behavior, instead of deleting everything and breaking the entire project, it simply crosses out that line of code, like crossing out a sentence in a notebook.
The false positives are mostly my interpretation and logic. A script has file writing capabilities, BUT it exists for some reason, whether it's due to an algorithm or menus, so it's added to a whitelist. The best example I can give you is Poiyomi.
Poiyomi uses many scripts that write to files/directories. This is where I check if that script exists in the official project, extract a unique hash (the file signature), and add it to a whitelist. This way, when an avatar's project is scanned and a Poiyomi file is found within it, I verify that the same file exists in the official project. If it does, it's skipped.
BUT, this doesn't mean the scanner says, "Ah, this file exists, I'll skip it." It verifies that the content is the same as in the official project using the file's hash.
Currently, many flags were created by an AI that thoroughly investigated all possible scenarios, such as HTTP injection, file writing, out-of-the-box code, disguised files, etc. However, over time, the criteria for what is considered critical or high, and their corresponding scores, are being updated.
-
New version v0.8.0
I've fixed the false positives that were generating audio files; for example, a project that had 126 warnings now only has 1. We're still working on reducing false positives so that eventually only real warnings will appear lol
https://github.com/vicentefelipechile/vrchat-scanner/releases
Web Version
I've also worked on a web version of this scanner for those who don't want to download a file. The web version includes a scan history, making it easier to share results. It also supports Discord embeds.
https://scanner.vrcstorage.lat/
Again, ty!! @anonberry for all ideas :3
-
Working on the version 0.9.0
Currently, the scan only has the bare minimum to function, but not everyone knows how to use a terminal, so I'm preparing a new version that includes an easy-to-use interface and runs everything locally.
This is my first time making a desktop application (without using a frontend), so you can expect to find some bugs.
Preview



-
Working on the version 0.9.0
Currently, the scan only has the bare minimum to function, but not everyone knows how to use a terminal, so I'm preparing a new version that includes an easy-to-use interface and runs everything locally.
This is my first time making a desktop application (without using a frontend), so you can expect to find some bugs.
Preview



-
@anonberry tyyy!!!
-
Version 0.9.0
I finished to build a desktop version for the scanner, now you can easily scan unitypackages, see their score, file tree and even export the content inside as ZIP or folder.
You can use it by downloading the installer from the releases
https://github.com/vicentefelipechile/vrchat-scanner/releases
Preview







-
It comes with their own icon btw

-
It comes with their own icon btw

Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login