SafeDep
Install GitHub App
SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to data exfiltration to a hardcoded IP, command execution, suspicious install scripts, and few published versions.

Verification Record

The package is marked as malware by OSV: MAL-2026-1381 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple strong indicators of malicious behavior. The callback.js file contains code to collect sensitive system information (hostname, username, IP addresses, OS details, CI environment variables) and exfiltrate it to a hardcoded IP address (168.220.234.152) via HTTP POST/GET requests and DNS queries. The package.json file includes preinstall and postinstall scripts that execute callback.js, allowing arbitrary code execution during installation. The package also has very few published versions, which may indicate malicious intent. The combination of data exfiltration, command execution, and suspicious install scripts strongly suggests that this package is malicious.

@immuta/feature-flags-core@99.99.0Malicious
Verified
Analysed at: 3/13/26, 5:34 AM
Source: https://registry.npmjs.org/@immuta/feature-flags-core/-/feature-flags-core-99.99.0.tgz
SHA256: 3bfa784935eb3e3725259ffa0385a1e06d8aa7f5badf4f3b67d60eeb3b62fa30
Confidence: High