SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to code obfuscation, dynamic module loading, process exposure, suspicious install script, and untrustworthy author email.

Verification Record

The package is marked as malware by OSV: MAL-2026-2407 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple indicators of malicious behavior. The code uses hex obfuscation in multiple files (6ad264.js, b02e30.js, helpers.js) to hide its functionality. The 6ad264.js file dynamically loads core Node.js modules like 'os', 'dns', and 'process', and exposes the process object which can be used to access sensitive information. The package.json includes a suspicious install script (node index.js) that executes arbitrary code during installation. The author's email research@sl4x0.xyz uses a suspicious domain. While the project has low stars/forks and few published versions, the combination of code obfuscation, dynamic loading of modules, process object exposure, and a suspicious install script strongly suggests malicious intent.

@ceeferenderer/itg-renderer-sdk@99.9.9Malicious
Verified
Analysed at: 3/14/26, 7:10 PM
Source: https://registry.npmjs.org/@ceeferenderer/itg-renderer-sdk/-/itg-renderer-sdk-99.9.9.tgz
SHA256: 3e0fcf58653c81f0c9d75c482a132f4926d33990070c58bbb2e7629d1468f28d
Confidence: High