SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Package classified as malware due to code obfuscation, use of eval() for code execution, and a low number of published versions.

Verification Record

The package is marked as malware by OSV: MAL-2026-1483 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious characteristics. The js_hex_obfuscation YARA rule detected obfuscation in lib.js. Additionally, the LLM analysis identified the use of eval() to execute a dynamically generated string, which is a strong indicator of potential malicious behavior. The package also has very few published versions, which can be a sign of low maintenance or malicious intent. Combining these factors, the package is classified as malware.

@jaime9008/math-service@1.0.2Malicious
Verified
Analysed at: 2/23/26, 2:12 AM
Source: https://registry.npmjs.org/@jaime9008/math-service/-/math-service-1.0.2.tgz
SHA256: 74eda1b7e3eed89ea4133ba15e51eeba8dc6d42077e41bb1c06fcc5abaa65a2c
Confidence: High