SafeDep
Install GitHub App

Summary

Single low confidence YARA match 'xor_url' is not enough to classify as malware. Legitimate obfuscation is possible.

Verification Record

No verification record available.

Details

The single YARA rule match 'xor_url' with low confidence is not sufficient to classify the package as malware. While XOR encryption can be used to hide malicious URLs, it's also employed for legitimate obfuscation purposes. The presence of various URL-related patterns doesn't automatically indicate malicious intent. Without stronger evidence, it's safer to assume this is not a malware.

recharts@3.5.0Clean
Unverified
Analysed at: 11/23/25, 5:50 AM
Source: https://registry.npmjs.org/recharts/-/recharts-3.5.0.tgz
SHA256: 985038c564f29ee22df45a0009d02efe3dfb35e1c46121ddc37f6a89c2cbe542
Confidence: Medium