SafeDep
Install GitHub App
SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package detected. Suspicious preinstall script exfiltrates data to a remote server. Multiple YARA rules and LLM analysis confirm.

Verification Record

The package is marked as malware by OSV: MAL-2026-1374 with source: ghsa-malware

Details

Note: This report is updated by a verification record

The package is classified as malware due to multiple strong indicators. The package.json file contains a preinstall script that executes commands to list the root directory, attempts to read flag files, and then exfiltrates this data to a remote server using curl. This behavior is detected by multiple YARA rules (npm_preinstall_command, npm_preinstall_curl) and confirmed by the LLM analysis, which identifies it as suspicious and indicative of data exfiltration. The low number of published versions further increases suspicion.

spectral-corsair-my-backdoor@99.99.101Malicious
Verified
Analysed at: 3/5/26, 4:33 PM
Source: https://registry.npmjs.org/spectral-corsair-my-backdoor/-/spectral-corsair-my-backdoor-99.99.101.tgz
SHA256: 8f8483f854d0aae1426a1c53972db97f6cea71769cc6c8b06de99e05b9e734c2
Confidence: High