Note: This report is updated by a verification record
Collects and exfiltrates sensitive data (env vars, SSH keys, keystores, history) via HTTPS and DNS. Suspicious domain and disabled SSL validation.
The package is marked as malware by OSV: MAL-2026-2499 with source: amazon-inspector
Note: This report is updated by a verification record
The package exhibits multiple malicious behaviors, strongly suggesting it is malware. It collects and exfiltrates sensitive information including environment variables, .env file contents, files from the user's home directory (including SSH keys and AWS credentials), cryptocurrency keystore files, and command history. It also checks for the existence of MetaMask browser extension data. The exfiltration occurs via HTTPS POST requests to c.npmjs-security.com with disabled SSL certificate validation and via DNS requests. Multiple YARA rules detected access to sensitive files and system information. The project also has very few published versions, which is a red flag. The combination of these factors provides strong evidence of malicious intent.