SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Package is malware. It exfiltrates data to a suspicious domain via callback.js, triggered by a preinstall script in package.json.

Verification Record

The package is marked as malware by OSV: MAL-2026-1318 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple strong indicators of malicious activity. The callback.js script sends system and package information to a suspicious domain, redirect.totally-not-malware.com, which is indicative of data exfiltration. The package.json file includes a preinstall script that executes node callback.js, enabling arbitrary code execution during installation. These factors, combined with the suspicious hostname, strongly suggest that the package is malicious.

@web-monorepo/fetchers@999.0.0Malicious
Verified
Analysed at: 3/7/26, 5:04 AM
Source: https://registry.npmjs.org/@web-monorepo/fetchers/-/fetchers-999.0.0.tgz
SHA256: 726d9916fc3c9c1ef8f7beda3a0ecafe04f57e3aaf55505a5a6c8da097756dfe
Confidence: High