SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

The package is flagged as malware due to the presence of a suspicious preinstall script (node index.js) in package.json.

Verification Record

The package is marked as malware by OSV: MAL-2026-1388 with source: ghsa-malware

Details

Note: This report is updated by a verification record

The package contains a preinstall script in package.json that executes node index.js. This behavior is flagged by both a YARA rule (npm_preinstall_command) and an LLM-based file evaluation service as suspicious. The preinstall script is a common technique used by malicious packages to execute arbitrary code during installation. This constitutes strong evidence of malicious intent, as it allows the package to run code without the user's explicit consent.

tourney-sdk-react@99.1.15Malicious
Verified
Analysed at: 3/11/26, 11:25 PM
Source: https://registry.npmjs.org/tourney-sdk-react/-/tourney-sdk-react-99.1.15.tgz
SHA256: f8ad930f9135a379135a7961e23a7a00407cbfcbe46dee17ff4b1fcbc2bea709
Confidence: High