SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Suspicious install script executing index.js and an untrustworthy author email domain sl4x0.xyz strongly suggest this package is malware.

Verification Record

The package is marked as malware by OSV: MAL-2026-2418 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits suspicious characteristics that, when combined, suggest malicious intent. The install script executes node index.js, which is a strong indicator of potential malicious behavior. Additionally, the author's email domain, sl4x0.xyz, raises further suspicion due to its lack of association with any legitimate organization. The combination of these two factors leads to the conclusion that the package is likely malware.

tombac-chronos@9.9.9Malicious
Verified
Analysed at: 3/3/26, 2:13 PM
Source: https://registry.npmjs.org/tombac-chronos/-/tombac-chronos-9.9.9.tgz
SHA256: 841c81f22c7e775f6804dc52e4b9abe375c7efe7c09d221606cc18bdd4615e40
Confidence: High