Note: This report is updated by a verification record
Malicious package due to code obfuscation, dynamic code execution, suspicious email, install script, and low project popularity.
The package is marked as malware by OSV: MAL-2026-2417 with source: amazon-inspector
Note: This report is updated by a verification record
The package exhibits multiple suspicious characteristics that, when combined, strongly suggest malicious intent. These include:
module.constructor._load to dynamically load modules. This is another technique used to hide malicious behavior and evade detection.process object allows the code to inspect the environment and potentially compromise the system.sl4x0.xyz is suspicious and lacks clear association with a legitimate organization.node index.js during installation, allowing arbitrary code execution immediately after installation.While individual aspects might not be conclusive, the combination of obfuscation, dynamic code execution, suspicious email, and install script strongly suggests that this package is malicious.