SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Package collects and exfiltrates sensitive system data to Oastify URLs. High entropy file and extension mismatch add to suspicion.

Verification Record

The package is marked as malware by OSV: MAL-2026-1233 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple indicators of malicious behavior. Both index.js and setup.py files contain code that collects sensitive system information (hostname, username, current directory, DNS servers, etc.) and transmits it to external servers using Oastify URLs (https://t939aacpj98mgkavtuj7xzvnwe25qwhk6.oastify.com and https://zjmfkgmvtfisqqk130td755t6kcb0go5.oastify.com). The LLM analysis confirms this data exfiltration. Additionally, the YARA rule very_high_entropy matched a file, and there's an extension mismatch in one of the files, further raising suspicion. The combination of these factors strongly suggests malicious intent.

projectrtert@1.0.0Malicious
Verified
Analysed at: 2/25/26, 5:10 AM
Source: https://registry.npmjs.org/projectrtert/-/projectrtert-1.0.0.tgz
SHA256: 51e44bf10a99230bc893be23442d8c4f3393301c9c4e6d6e0b25bda6d36c7ad0
Confidence: High