SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Package collects and exfiltrates sensitive info to oastify.com via HTTP in both index.js and setup.py with silent error handling. Likely malware.

Verification Record

The package is marked as malware by OSV: MAL-2026-1027 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple indicators of malicious behavior. Both index.js and setup.py files contain code that collects sensitive information (hostname, username, current directory, DNS servers, package information) and transmits it to external servers via HTTP requests to oastify.com domains. The use of oastify.com, a service for detecting out-of-band interactions, coupled with silent error handling in index.js and the collection of sensitive information, strongly suggests malicious intent. The pysetup_gets_login YARA rule match on setup.py further supports this conclusion. The fact that the project has very few published versions also raises suspicion.

rtxbbtyols@1.0.0Malicious
Verified
Analysed at: 2/24/26, 7:18 AM
Source: https://registry.npmjs.org/rtxbbtyols/-/rtxbbtyols-1.0.0.tgz
SHA256: 6d7b3deade85df61e6a204d8ab586aa280a9625b1b0e5b8d8112574bac78a3ae
Confidence: High