SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple evidences suggest malicious intent: code obfuscation, dynamic code execution, process access, install script, and suspicious email.

Verification Record

The package is marked as malware by OSV: MAL-2026-2406 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. Firstly, the presence of hex obfuscation in multiple javascript files (6ad264.js, b02e30.js, and helpers.js) indicates an attempt to conceal the code's functionality. The LLM analysis confirms this, highlighting code obfuscation and dynamic code execution using module.constructor._load. Secondly, the package accesses the global process object, which is often used by malware for system information gathering or manipulation. Thirdly, the package.json contains an install script that executes node index.js, allowing arbitrary code execution during installation. Finally, the author's email address research@sl4x0.xyz is suspicious. These factors combined strongly suggest malicious intent.

@ceeferenderer/fe-renderer-sdk@99.9.9Malicious
Verified
Analysed at: 3/14/26, 7:09 PM
Source: https://registry.npmjs.org/@ceeferenderer/fe-renderer-sdk/-/fe-renderer-sdk-99.9.9.tgz
SHA256: bb9854fd8f8e320afb9a6026bcd45011e64c96c4624da962049148b4d58c18c2
Confidence: High