SafeDep
Install GitHub App
SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Potentially malicious package due to embedded executable with mismatched extension and arbitrary code execution during installation.

Verification Record

Package compromised via npm token leak from phishing attack

Details

Note: This report is updated by a verification record

The package contains a DLL with a mismatched extension (likely an EXE renamed to DLL) and executes arbitrary code during installation via install.cjs. This combination of suspicious behaviors suggests malicious intent. Embedding an executable and running code on install are common malware techniques.

@pkgr/core@0.2.8Malicious
Verified
Analysed at: 7/18/25, 5:26 PM
Source: https://registry.npmjs.org/@pkgr/core/-/core-0.2.8.tgz
SHA256: 648babe3d058cfebd0dc325b1317536c08f02096254fc951a92ef61d326e689f
Confidence: High