SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

The package downloads/executes payloads from remote URLs, executes arbitrary commands, and attempts self-deletion, indicating malicious intent.

Verification Record

WAVESHAPER.V2 / UNC1069 (Sapphire Sleet) - compromised npm package delivering multi-platform RAT via account takeover

Details

Note: This report is updated by a verification record

The package exhibits multiple behaviors indicative of malicious intent. It downloads and executes payloads from remote URLs on macOS, Windows, and Linux (Evidences 4, 5, 6, 7). It also executes arbitrary commands based on the OS platform (Evidence 8) and attempts to delete itself and other files (Evidence 9). YARA rules further confirm the use of PowerShell with hidden commands, nohup with bash, and modification of file permissions to be group writeable and executable (Evidences 0, 1, 2). The combination of these factors strongly suggests that the package is malicious.

mgc@1.2.4Malicious
Verified
Analysed at: 4/2/26, 6:46 AM
Source: https://registry.npmjs.org/mgc/-/mgc-1.2.4.tgz
SHA256: 40aa5d412a50db79a814ac5ad65237745727cb4777843d66a760f64285a5a3e6
Confidence: High