SafeDep
Install GitHub App
SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Package is malware. Hardcoded Telegram credentials, data exfiltration, and preinstall script execution indicate malicious intent.

Verification Record

The package is marked as malware by OSV: MAL-2026-2523 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package is a malware because it exhibits multiple strong indicators of malicious behavior. The index.js file contains hardcoded Telegram bot credentials and exfiltrates sensitive information like username, hostname, and current path to a Telegram bot. This is a clear sign of data exfiltration. Additionally, the package.json file includes a preinstall script that executes node index.js, enabling arbitrary code execution during installation, which is a common technique used by attackers. The combination of these factors strongly suggests that the package is malicious.

@telekom-wfa/auth-core@99.9.11Malicious
Verified
Analysed at: 4/4/26, 7:13 AM
Source: https://registry.npmjs.org/@telekom-wfa/auth-core/-/auth-core-99.9.11.tgz
SHA256: 31c8c7259d6bb60c0be18a4fad829d1c7ff8c8e2a900f11b4e1df9869fe25c79
Confidence: High