SafeDep
Install GitHub App
Start for Free
SafeDep
Install GitHub App
Start for Free

Summary

Multiple low confidence YARA rule matches, but no strong evidence to classify as malware. Likely false positives.

Verification Record

No verification record available.

Details

The package is not a malware. While multiple YARA rules matched across several files, the confidence level for each match is low. Specifically, js_hex_obfuscation, py_dropper_chmod, and dev_shm_file rules matched, but there is no strong evidence to suggest malicious intent. The py_dropper_chmod rule is designed to detect Python droppers, but it's matching on JavaScript files, which is often a false positive. Similarly, the presence of dev_shm_file and js_hex_obfuscation alone is insufficient to classify the package as malware.

@jitl/quickjs-wasmfile-debug-sync@0.32.0Clean
Unverified
Analysed at: 2/16/26, 4:49 AM
Source: https://registry.npmjs.org/@jitl/quickjs-wasmfile-debug-sync/-/quickjs-wasmfile-debug-sync-0.32.0.tgz
SHA256: f7647394d273bde2df910f5a1dac2e7aa6ac9bd0adedd338ce6d70d67ea62624
Confidence: Medium