SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple suspicious behaviors: postinstall script, hex obfuscation, OS command execution to open a Rickroll, and attempt to hide execution.

Verification Record

The package is marked as malware by OSV: MAL-2026-2500 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. The postinstall script executes setup.js (Evidence 2), which contains hex-obfuscated code (Evidence 0) and executes OS commands to open a YouTube video (Evidence 1). While the video is a Rickroll and not inherently malicious, the combination of these factors, including obfuscation and unexpected OS command execution, suggests malicious intent. The detached: true and windowsHide: true options further indicate an attempt to conceal the script's activity.

totally-safe-util@1.0.4Malicious
Verified
Analysed at: 4/6/26, 9:20 AM
Source: https://registry.npmjs.org/totally-safe-util/-/totally-safe-util-1.0.4.tgz
SHA256: 144e54f6bb102935a59769e22353b4d87d5d1b46655bd5bd725bc6793525d01c
Confidence: High