SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Package is malware due to ransomware-like behavior: file encryption, key exfiltration, terminal locking, ransom note, and persistence attempts.

Verification Record

The package is marked as malware by OSV: MAL-2026-1319 with source: ghsa-malware

Details

Note: This report is updated by a verification record

The package exhibits multiple strong indicators of malicious behavior, specifically ransomware. It encrypts files (Evidence 3, 4), exfiltrates the encryption key to a Telegram bot (Evidence 2, 6), locks the terminal (Evidence 8), displays a ransom note (Evidence 9), and attempts to persist via shell configuration modification (Evidence 1, 7, 10, 11). The postinstall script executes code upon installation (Evidence 12). These combined behaviors strongly suggest malicious intent.

alinet-w@2.0.0Malicious
Verified
Analysed at: 3/8/26, 1:31 PM
Source: https://registry.npmjs.org/alinet-w/-/alinet-w-2.0.0.tgz
SHA256: 0c04e12fd6f73ffa69e583fb13dffc554e0a218ef85d36aa243d5c31a13c2978
Confidence: High