SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple evidences indicate malicious behavior: suspicious URL, data exfiltration, process exiting, and preinstall script execution.

Verification Record

The package is marked as malware by OSV: MAL-2026-1232 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. The preinstall script executes scripts/setup.js, allowing arbitrary code execution before installation (Evidence 4). This script makes a request to a suspicious domain edrxkprbcqxvbhveoqmmpxavp9wwhkqy4.gjq.io (Evidence 0), exfiltrates the hostname and current working directory (Evidence 1), and then exits the process (Evidence 2). The YARA rule npm_preinstall_command is also triggered (Evidence 3). The combination of these factors indicates malicious intent.

@schedaero/yukon@99440.540.1Malicious
Verified
Analysed at: 2/25/26, 6:11 AM
Source: https://registry.npmjs.org/@schedaero/yukon/-/yukon-99440.540.1.tgz
SHA256: c5f7edf9be7bd0e016e786fb06cdb5371cdf1b5495372646686bba6f0b857885
Confidence: High