SafeDep
Install GitHub App
SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple pieces of evidence suggest malicious intent: hex obfuscation, dynamic code execution, suspicious email, and install script executing index.js.

Verification Record

The package is marked as malware by OSV: MAL-2026-2415 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors that, when combined, strongly suggest malicious intent. The presence of hex-obfuscated JavaScript code in 6ad264.js and b02e30.js, combined with the dynamic code execution using module.constructor._load to load os and dns modules and accessing the global process object, indicates an attempt to hide malicious activities. The suspicious author email domain "sl4x0.xyz" and the execution of node index.js during installation further reinforce this assessment. The install script allows for arbitrary code execution during installation, which is a common malware technique. The combination of these factors points towards a high likelihood of malicious behavior.

oc-aa-module-client@9.9.10Malicious
Verified
Analysed at: 3/22/26, 8:50 AM
Source: https://registry.npmjs.org/oc-aa-module-client/-/oc-aa-module-client-9.9.10.tgz
SHA256: 634a4e661ebf31f69c27aa911816eaaf927144dc684a7416f62d801c0ca575b3
Confidence: High