Note: This report is updated by a verification record
Malicious package due to hex obfuscation, dynamic module loading, process access, suspicious install script, and untrustworthy project.
The package is marked as malware by OSV: MAL-2026-2411 with source: amazon-inspector
Note: This report is updated by a verification record
The package exhibits multiple suspicious behaviors strongly suggesting it is malware. It uses hex obfuscation in 6ad264.js and b02e30.js. It converts arrays of numbers to strings, loads modules dynamically using module.constructor['_load'] for 'os' and 'dns', and accesses the global process object. The install script in package.json executes arbitrary code (node index.js) during installation. The author email research@sl4x0.xyz uses a suspicious domain. The project has low stars/forks and has published few versions.