SafeDep
Install GitHub App

Summary

Single low-confidence YARA match 'python_exec_near_enough_decrypt' is insufficient to classify as malware given project popularity and provenance.

Verification Record

No verification record available.

Details

The package @next/env version 16.0.5 from the vercel/next.js project, which has a substantial number of stars and forks, exhibits a YARA rule match python_exec_near_enough_decrypt in index.js. While this suggests the potential execution of encrypted content, it is a single piece of evidence with low confidence. Without further corroborating evidence, it is insufficient to classify the package as malware. The project's popularity and the presence of SLSA provenance also suggest a lower risk of malicious intent.

@next/env@16.0.5Clean
Unverified
Analysed at: 11/27/25, 7:47 AM
Source: https://registry.npmjs.org/@next/env/-/env-16.0.5.tgz
SHA256: aa8addd3bd200c271dc0a8d82825ef7f2d087eba0fc8bc6333192e9b1a8bef85
Confidence: Medium