SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple evidences indicate malicious behavior: obfuscation, suspicious install script, access to sensitive functionalities, and untrustworthy source.

Verification Record

The package is marked as malware by OSV: MAL-2026-2409 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple strong indicators of malicious behavior. The presence of hex obfuscation in 6ad264.js and b02e30.js (Evidences 0 and 4), combined with the use of String.fromCharCode to deobfuscate strings and access sensitive functionalities like module.constructor._load (Evidences 1, 2), strongly suggests malicious intent. The access to the global process object (Evidence 3) further raises concerns. The suspicious install script executing node index.js (Evidence 5) is highly unusual and indicative of arbitrary code execution during installation. The suspicious author email (Evidence 6) adds to the overall suspicion. While low popularity of the project (Evidences 7 and 8) alone isn't conclusive, it reinforces the other evidence pointing towards malicious activity.

@phonos/types@9.9.10Malicious
Verified
Analysed at: 3/24/26, 9:00 AM
Source: https://registry.npmjs.org/@phonos/types/-/types-9.9.10.tgz
SHA256: c4641385b62e71645ab01f75447689924402d154309400570035edae3cce8aae
Confidence: High