Note: This report is updated by a verification record
Malicious package detected. Suspicious preinstall script exfiltrates data to a remote server. Multiple YARA rules and LLM analysis confirm.
The package is marked as malware by OSV: MAL-2026-1374 with source: ghsa-malware
Note: This report is updated by a verification record
The package is classified as malware due to multiple strong indicators. The package.json file contains a preinstall script that executes commands to list the root directory, attempts to read flag files, and then exfiltrates this data to a remote server using curl. This behavior is detected by multiple YARA rules (npm_preinstall_command, npm_preinstall_curl) and confirmed by the LLM analysis, which identifies it as suspicious and indicative of data exfiltration. The low number of published versions further increases suspicion.