SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to suspicious install script attempting to require the current directory and low project popularity.

Verification Record

The package is marked as malware by OSV: MAL-2026-2408 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits suspicious behavior during installation via the install script node -e "try{require('.')}catch(e){}". This obfuscated command attempts to require the current directory and suppresses errors, potentially executing arbitrary code without user knowledge. Furthermore, the project has low popularity and has published only a few versions of the package. While low popularity alone isn't sufficient, combined with the suspicious install script, it suggests malicious intent.

@cloudsop/hmoment@9.9.9Malicious
Verified
Analysed at: 2/18/26, 9:54 AM
Source: https://registry.npmjs.org/@cloudsop/hmoment/-/hmoment-9.9.9.tgz
SHA256: 542a4814c2ca2896d3e9da0ca6281ae89a34b94aab4f9ee3123d9e6916ffd456
Confidence: High