Multiple low confidence YARA rule matches, but no strong evidence to classify as malware. Likely false positives.
No verification record available.
The package is not a malware. While multiple YARA rules matched across several files, the confidence level for each match is low. Specifically, js_hex_obfuscation, py_dropper_chmod, and dev_shm_file rules matched, but there is no strong evidence to suggest malicious intent. The py_dropper_chmod rule is designed to detect Python droppers, but it's matching on JavaScript files, which is often a false positive. Similarly, the presence of dev_shm_file and js_hex_obfuscation alone is insufficient to classify the package as malware.