SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple suspicious behaviors: hex obfuscation, code execution via constructor, process access, install script, and suspicious author email.

Verification Record

The package is marked as malware by OSV: MAL-2026-2414 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious characteristics indicative of malware. The presence of hex obfuscation in multiple JavaScript files (6ad264.js, b02e30.js, helpers.js) makes the code harder to read and analyze. The 6ad264.js file uses module.constructor to load modules like os and dns, which is a common technique for code execution. It also accesses the global process object, potentially enabling malicious actions. The package.json includes an install script that executes node index.js upon installation, and the author email research@sl4x0.xyz uses a suspicious domain. These multiple pieces of evidence strongly suggest malicious intent.

ftapi-core@99.9.9Malicious
Verified
Analysed at: 3/14/26, 3:20 PM
Source: https://registry.npmjs.org/ftapi-core/-/ftapi-core-99.9.9.tgz
SHA256: 27b73eeefe94c05565c59ede06893837ef01227824692cb3753d289860fc7ac7
Confidence: High