SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to suspicious preinstall script, data exfiltration via User-Agent, process termination, and a suspicious URL. Low version count.

Verification Record

The package is marked as malware by OSV: MAL-2026-1229 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors that, when combined, strongly suggest malicious intent. Specifically, the preinstall script executes node scripts/setup.js, which makes a suspicious HTTP request to https://edrxkprbcqxvbhveoqmmpxavp9wwhkqy4.gjq.io/, potentially for data exfiltration or malicious payload download. The script also sends hostname and current working directory in the User-Agent, further indicating data exfiltration. Furthermore, the script terminates the process after the callback request, which is unusual and disruptive. The low number of published versions adds to the suspicion. These multiple indicators point towards malicious activity.

@schedaero/net-common@99440.540.1Malicious
Verified
Analysed at: 2/25/26, 6:10 AM
Source: https://registry.npmjs.org/@schedaero/net-common/-/net-common-99440.540.1.tgz
SHA256: 63d362b49f33a5df51ba092e3f082a5b066bce59e9db10409f0999a03f24b8ee
Confidence: High