SafeDep
Install GitHub App
Start for Free
SafeDep
Install GitHub App
Start for Free

Summary

Insufficient evidence to classify as malware; YARA findings are inconclusive, and LLM analysis is missing.

Verification Record

No verification record available.

Details

While the YARA analysis flagged suspicious patterns in the package's files (Evidence 0 and Evidence 1), these matches are considered noisy and unreliable by themselves. The YARA rules detected unsigned bitwise math and SVG content with potentially embedded scripts, but these are not definitive indicators of malicious behavior. Many legitimate applications may use such techniques. The low number of project versions and low popularity of the source project (Evidence 2 and 3) raise concerns about the package's maturity and trustworthiness, but these are not conclusive evidence of malware. The absence of LLM-based file analysis, which is considered more reliable than YARA, prevents a definitive conclusion. Therefore, based on the available evidence, a conclusive determination of malicious intent cannot be made.

@mixmark-io/domino@2.2.0Clean
Unverified
Analysed at: 5/2/25, 6:01 AM
Source: https://registry.npmjs.org/@mixmark-io/domino/-/domino-2.2.0.tgz
SHA256: b829bcca09544649f6432020dd6915b6fb054154d7a77eb6f8b3fb1f4165afec
Confidence: Medium