SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to data exfiltration, arbitrary code execution during installation via preinstall script, and suspicious hostname.

Verification Record

The package is marked as malware by OSV: MAL-2026-1484 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple strong indicators of malicious behavior. It exfiltrates sensitive information (hostname, platform, username) to a suspicious external server ('tu-webhook-o-servidor.com'). Additionally, it executes arbitrary code during the preinstall phase via node index.js, a common technique used by malicious packages. The package also has very few published versions. The combination of data exfiltration, arbitrary code execution during installation, and a suspicious hostname strongly suggests malicious intent.

internal-lib-vulnerable@99.9.9Malicious
Verified
Analysed at: 3/16/26, 10:01 AM
Source: https://registry.npmjs.org/internal-lib-vulnerable/-/internal-lib-vulnerable-99.9.9.tgz
SHA256: 872b392310f5b25d314ef9dc7bb8b207709b639ec9a89d2df48cb9718ef7c157
Confidence: High