SafeDep
Install GitHub App

Summary

Package is not malware. Low confidence YARA matches and potential DoS/XSS vulnerabilities are not definitive signs of malicious intent.

Verification Record

No verification record available.

Details

The package is not a malware. Although multiple YARA rules are triggered, specifically multi_decode_3 and sys_net_recon_exfil, these have low confidence. Also, the LLM based file evaluation service identified potential DoS and XSS vulnerabilities via regular expressions, but these are potential vulnerabilities and not definitive signs of malicious intent. The next package is a complex piece of software, and the identified behaviors could be part of its normal operation, especially considering the lack of provenance information.

next@16.0.7Clean
Unverified
Analysed at: 12/3/25, 3:19 PM
Source: https://registry.npmjs.org/next/-/next-16.0.7.tgz
SHA256: 5ac409220699cd99d3e3af54bfb59bcf29a286aaa27899237273afc04219fa3c
Confidence: Medium