SafeDep
Install GitHub App

Summary

Multiple 'password_finder_generic' YARA matches and untrustworthy source project indicate potential malicious activity.

Verification Record

No verification record available.

Details

The package has multiple YARA rule matches for 'password_finder_generic' in src/main.cc, lib/keytar.js, README.md, and keytar.d.ts. This indicates a potential attempt to find or dump passwords. Additionally, the source project has low stars and forks, making it less trustworthy. While each YARA match alone might not be conclusive, the combination of multiple matches and an untrustworthy source project raises significant concerns.

@postman/node-keytar@7.9.2Suspicious
Unverified
Analysed at: 11/25/25, 6:17 AM
Source: https://registry.npmjs.org/@postman/node-keytar/-/node-keytar-7.9.2.tgz
SHA256: 1b7ac1ca281d6b7964d6595290cb5897b3725abe2a97b9ccb381a577fdeaf39b
Confidence: Medium