SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple evidences suggest this package is a malware: code obfuscation, dynamic code execution, suspicious domain, and unusual install script.

Verification Record

The package is marked as malware by OSV: MAL-2026-2413 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple strong indicators of malicious behavior. The presence of hex obfuscation in 6ad264.js and b02e30.js (Evidences 0, 1, 5, 6, 8) combined with dynamic code execution using module.constructor._load (Evidence 2), access to the global process object (Evidence 3), and the export of OS, DNS, and Process objects (Evidence 4) raise significant concerns. Furthermore, the obfuscation of a domain name 'oob.sl4x0.xyz' (Evidences 7, 9), a suspicious author email domain 'sl4x0.xyz' (Evidence 10), and the highly unusual 'install' script executing 'node index.js' (Evidence 11) collectively point towards malicious intent. The combination of these factors strongly suggests that this package is designed to perform malicious actions.

cclr-component-resources@9.9.10Malicious
Verified
Analysed at: 3/22/26, 8:51 AM
Source: https://registry.npmjs.org/cclr-component-resources/-/cclr-component-resources-9.9.10.tgz
SHA256: cbb721c9629c27f219929647bfd09971892761012190e86c5f7329c96fc9c0b3
Confidence: High