SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to preinstall script execution, system info gathering, Discord webhook usage for data exfiltration, and error suppression.

Verification Record

The package is marked as malware by OSV: MAL-2026-1487 with source: ghsa-malware

Details

Note: This report is updated by a verification record

The package is highly likely to be malware due to multiple strong indicators. The package.json includes a preinstall script executing node payload.js, enabling arbitrary code execution before installation. The payload.js script gathers sensitive system information (hostname, username, platform, Node.js version, cwd) and sends it to a Discord webhook. The script also suppresses error messages, hindering detection of failed requests. These behaviors, combined with the use of a Discord webhook for data exfiltration, strongly suggest malicious intent.

vitest-config@99.0.3Malicious
Verified
Analysed at: 3/13/26, 7:08 PM
Source: https://registry.npmjs.org/vitest-config/-/vitest-config-99.0.3.tgz
SHA256: 44b2758c0f7e0b4ec0973e82ea0f6d2e2ca9ecb26127731b48d2af4cace84bca
Confidence: High