SafeDep
Install GitHub App
SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to data exfiltration, command execution, and suspicious install scripts. Gathers system info and sends it to a remote server.

Verification Record

The package is marked as malware by OSV: MAL-2026-1382 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple strong indicators of malicious behavior. The callback.js file gathers sensitive system information (hostname, OS details, IP addresses, DNS servers, etc.) and attempts to exfiltrate this data via HTTP POST/GET requests and DNS queries to a suspicious IP address (168.220.234.152). It also executes shell commands using execSync, allowing arbitrary code execution. Furthermore, the package.json includes preinstall and postinstall scripts that execute callback.js, enabling code execution during installation. The combination of information gathering, data exfiltration, command execution, and installation script abuse strongly suggests malicious intent. The project also has very few published versions, which increases the risk.

@immuta/flag-providers-web@99.99.0Malicious
Verified
Analysed at: 3/13/26, 5:28 AM
Source: https://registry.npmjs.org/@immuta/flag-providers-web/-/flag-providers-web-99.99.0.tgz
SHA256: 0c186b689faa58863b609720b2c67d2ffd8565470c07e20b4f018e6a13408846
Confidence: High