SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

The package is malicious due to a postinstall script executing a file that exfiltrates sensitive information to a remote server.

Verification Record

The package is marked as malware by OSV: MAL-2026-1486 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple strong indicators of malicious behavior. The postinstall script executes node a.js, which is a common malware technique. The a.js file then makes multiple HTTP GET requests to https://site.wheezy.io/trello-enterprises-1000.1000.1000 exfiltrating sensitive information such as the current directory, hostname, username, and home directory. The YARA rule get_hardcoded_hardcoded_host_os also matched on a.js, further supporting the conclusion that this package is malicious.

trello-enterprises@1000.1000.1000Malicious
Verified
Analysed at: 3/16/26, 10:04 AM
Source: https://registry.npmjs.org/trello-enterprises/-/trello-enterprises-1000.1000.1000.tgz
SHA256: 23b7caef8cf1c966392dfe88d7a5278630714aceb74a932fe2cbdb113f53bec9
Confidence: High