SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple suspicious behaviors: preinstall script exfiltrates data to a suspicious URL, terminates process, and few versions. Strong evidence of malware.

Verification Record

The package is marked as malware by OSV: MAL-2026-1228 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors, strongly suggesting it is malware. The preinstall script executes scripts/setup.js, which exfiltrates sensitive information (hostname, CWD, Node.js version) to a suspicious URL. The script also terminates the process after the callback, which is unusual and could be used to hide malicious activity. The package has only a few published versions, further increasing suspicion. These factors combined provide strong evidence of malicious intent.

@schedaero/bacon@99440.540.1Malicious
Verified
Analysed at: 2/25/26, 6:11 AM
Source: https://registry.npmjs.org/@schedaero/bacon/-/bacon-99440.540.1.tgz
SHA256: 0e7972575a290a0326b1b0bab8bc4ddf9e3256b2ffcd690eef1679a754d688bd
Confidence: High