SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to suspicious callback URL, hostname exfiltration, preinstall script execution, and only one published version.

Verification Record

The package is marked as malware by OSV: MAL-2026-2524 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. The index.js file contains a suspicious callback URL (dwpmxufjontejuultjhe0dcw571lqawco.oast.fun) used for potential data exfiltration, as detected by both YARA and LLM analysis. It also attempts to exfiltrate the hostname. Additionally, the package.json file includes a preinstall script that executes node index.js, enabling arbitrary code execution during installation. The package has only one published version, raising further suspicion. The combination of these factors strongly suggests malicious intent.

a2a-chat-canvas@97.9.9Malicious
Verified
Analysed at: 4/5/26, 1:30 PM
Source: https://registry.npmjs.org/a2a-chat-canvas/-/a2a-chat-canvas-97.9.9.tgz
SHA256: b95a0b3c6093e3915c18c1018552c90d003c12eedda79e35aaa56fc7ae1e8589
Confidence: High