Note: This report is updated by a verification record
Malicious package detected due to the presence of a preinstall script (node index.js) in package.json, enabling arbitrary code execution.
The package is marked as malware by OSV: MAL-2026-1389 with source: ghsa-malware
Note: This report is updated by a verification record
The package contains a preinstall script in package.json that executes node index.js. This is a strong indicator of potential malicious behavior because it allows arbitrary code execution during installation. The LLM also flags the description as suspicious. Given the combination of these two evidences, the package is classified as malware.