SafeDep
Install GitHub App
SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to hex obfuscation, dynamic module loading, process access, suspicious install script, and untrustworthy project.

Verification Record

The package is marked as malware by OSV: MAL-2026-2411 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors strongly suggesting it is malware. It uses hex obfuscation in 6ad264.js and b02e30.js. It converts arrays of numbers to strings, loads modules dynamically using module.constructor['_load'] for 'os' and 'dns', and accesses the global process object. The install script in package.json executes arbitrary code (node index.js) during installation. The author email research@sl4x0.xyz uses a suspicious domain. The project has low stars/forks and has published few versions.

@wame/ngx-adfs@9.9.11Malicious
Verified
Analysed at: 3/22/26, 8:47 AM
Source: https://registry.npmjs.org/@wame/ngx-adfs/-/ngx-adfs-9.9.11.tgz
SHA256: c2941b823d635999a4c5fbd26941cea21b01bcb90d2e69dbf20b7283b2850703
Confidence: High