SafeDep
Install GitHub App

Summary

The YARA rule js_hex_obfuscation matched a *.go file, likely a false positive. Insufficient evidence to classify as malware.

Verification Record

No verification record available.

Details

The YARA rule js_hex_obfuscation matched a *.go file. This is likely a false positive because the rule is designed to detect JavaScript obfuscation, but it's matching a Go file. There is only one piece of evidence, which is not sufficient to classify the package as malware.

google.golang.org/protobuf@1.36.10Clean
Unverified
Analysed at: 10/8/25, 11:21 AM
Source: https://proxy.golang.org/google.golang.org%2fprotobuf/@v/v1.36.10.zip
SHA256: 9265fbe7d073ca8571f1a9c4b8e8f20b244c35ad913346892d688e58fe4b1f22
Confidence: Medium