Note: This report is updated by a verification record
Malicious package due to JS obfuscation, dynamic code execution, OS/DNS access, suspicious install script, and untrustworthy project.
The package is marked as malware by OSV: MAL-2026-2412 with source: amazon-inspector
Note: This report is updated by a verification record
The package exhibits multiple suspicious behaviors indicative of malware. Specifically, the 6ad264.js file contains hex-obfuscated JavaScript code, dynamic code execution using module.constructor._load to load 'os' and 'dns' modules, and accesses the global process object. This allows for potential information gathering and system manipulation. Additionally, the package.json file includes an install script that executes index.js, raising concerns about arbitrary code execution upon installation. The project also has low popularity and few published versions, making it less trustworthy. These combined factors strongly suggest malicious intent.