SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple suspicious behaviors: suspicious URL, data exfiltration, process termination, preinstall script, and few published versions. Likely malware.

Verification Record

The package is marked as malware by OSV: MAL-2026-1230 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors that, when combined, strongly suggest malicious intent. The preinstall script executes scripts/setup.js, which sends a GET request to a suspicious URL (https://edrxkprbcqxvbhveoqmmpxavp9wwhkqy4.gjq.io/). This script also exfiltrates the hostname and current working directory via the User-Agent header. Furthermore, the script terminates the process immediately after the callback, which is unusual and could be an attempt to hide malicious activity. The combination of a suspicious URL, data exfiltration, and process termination after the callback, along with the use of a preinstall script and the project having few published versions, points towards malicious behavior.

@schedaero/react-core@99440.540.1Malicious
Verified
Analysed at: 2/25/26, 6:12 AM
Source: https://registry.npmjs.org/@schedaero/react-core/-/react-core-99440.540.1.tgz
SHA256: eab9d237a4b42a081c8a825234605b56f074deb01959b033b73c61dc7e173c57
Confidence: High