SafeDep
Install GitHub App

Summary

Multiple potential vulnerabilities found, but no definitive proof of malicious intent. Classifying as not malware due to lack of strong evidence.

Verification Record

No verification record available.

Details

The package exhibits several potential vulnerabilities, including XSS via javascript: URLs and dynamic script injection, a potential DoS vulnerability in cookie parsing, and potential code injection via crafted URLs. However, the YARA rule matches are of low confidence and the LLM-based analysis identifies potential vulnerabilities, not definitive proof of malicious intent. Without stronger evidence, classifying the package as malware is not justified. It is more likely that these are edge cases or vulnerabilities in the code that need to be addressed.

next@16.0.4Clean
Unverified
Analysed at: 11/24/25, 5:11 PM
Source: https://registry.npmjs.org/next/-/next-16.0.4.tgz
SHA256: b495f801fdc9a55a10f3cb3be3eccdfc126e9b25704f0ed0865a9719dd97a3cd
Confidence: Medium