SafeDep
Install GitHub App
SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Collects and exfiltrates sensitive data (env vars, SSH keys, keystores, history) via HTTPS and DNS. Suspicious domain and disabled SSL validation.

Verification Record

The package is marked as malware by OSV: MAL-2026-2499 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple malicious behaviors, strongly suggesting it is malware. It collects and exfiltrates sensitive information including environment variables, .env file contents, files from the user's home directory (including SSH keys and AWS credentials), cryptocurrency keystore files, and command history. It also checks for the existence of MetaMask browser extension data. The exfiltration occurs via HTTPS POST requests to c.npmjs-security.com with disabled SSL certificate validation and via DNS requests. Multiple YARA rules detected access to sensitive files and system information. The project also has very few published versions, which is a red flag. The combination of these factors provides strong evidence of malicious intent.

nerite-security-audit@1.0.4Malicious
Verified
Analysed at: 4/4/26, 8:02 AM
Source: https://registry.npmjs.org/nerite-security-audit/-/nerite-security-audit-1.0.4.tgz
SHA256: ad976cb27e4055c5287856378d04b6f526443f536ad8949d61db150f55a78f29
Confidence: High