SafeDep
Install GitHub App
SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to JS obfuscation, dynamic code execution, OS/DNS access, suspicious install script, and untrustworthy project.

Verification Record

The package is marked as malware by OSV: MAL-2026-2412 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors indicative of malware. Specifically, the 6ad264.js file contains hex-obfuscated JavaScript code, dynamic code execution using module.constructor._load to load 'os' and 'dns' modules, and accesses the global process object. This allows for potential information gathering and system manipulation. Additionally, the package.json file includes an install script that executes index.js, raising concerns about arbitrary code execution upon installation. The project also has low popularity and few published versions, making it less trustworthy. These combined factors strongly suggest malicious intent.

@wame/ngx-frf-utilities@9.9.11Malicious
Verified
Analysed at: 3/22/26, 8:47 AM
Source: https://registry.npmjs.org/@wame/ngx-frf-utilities/-/ngx-frf-utilities-9.9.11.tgz
SHA256: 7c760459c0fc0d28213773414ba3febbc9d8bc1d514b2f8c2bb9cdb985534a21
Confidence: High