SafeDep
Install GitHub App

Summary

Insufficient evidence to classify as malware. Low popularity doesn't equal maliciousness; further analysis needed.

Verification Record

No verification record available.

Details

Based on the provided evidence, there is insufficient information to classify minipass-collect (2.0.1) as malware. Evidence 0 highlights an 'Untrustworthy source project' due to low popularity and OpenSSF score. However, this is a low-confidence assessment and does not definitively indicate malicious intent. Low popularity does not automatically equate to maliciousness; it could simply reflect a niche or less widely adopted package. The absence of other evidence, such as suspicious code behavior detected by LLM analysis or YARA matches (despite acknowledging their limitations), prevents a conclusive malware determination. Further investigation, including static and dynamic analysis of the package's code, is necessary to reach a definitive conclusion.

minipass-collect@2.0.1Clean
Unverified
Analysed at: 3/10/25, 1:17 PM
Source: https://registry.npmjs.org/minipass-collect/-/minipass-collect-2.0.1.tgz
SHA256: 1a4d094d890b9fa542e1608a73bef29e90389fa8960e40441c5d25284d7c4097
Confidence: Medium