Note: This report is updated by a verification record
Multiple pieces of evidence suggest malicious intent: hex obfuscation, dynamic code execution, suspicious email, and install script executing index.js.
The package is marked as malware by OSV: MAL-2026-2415 with source: amazon-inspector
Note: This report is updated by a verification record
The package exhibits multiple suspicious behaviors that, when combined, strongly suggest malicious intent. The presence of hex-obfuscated JavaScript code in 6ad264.js and b02e30.js, combined with the dynamic code execution using module.constructor._load to load os and dns modules and accessing the global process object, indicates an attempt to hide malicious activities. The suspicious author email domain "sl4x0.xyz" and the execution of node index.js during installation further reinforce this assessment. The install script allows for arbitrary code execution during installation, which is a common malware technique. The combination of these factors points towards a high likelihood of malicious behavior.