SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to data exfiltration in preinstall script, suspicious repo URL, and a low number of published versions.

Verification Record

The package is marked as malware by OSV: MAL-2026-2511 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. The preinstall script in package.json executes node preinstall.js, which exfiltrates system information (hostname and git email) to an external server. The repository URL also points to a potentially attacker-controlled GitHub organization, indicating a possible supply chain attack. Additionally, the package has only one published version, which can be a sign of malicious intent. These combined factors strongly suggest that the package is malicious.

argon2-napi@1.0.0Malicious
Verified
Analysed at: 4/7/26, 12:15 PM
Source: https://registry.npmjs.org/argon2-napi/-/argon2-napi-1.0.0.tgz
SHA256: 7ab557ad77be072b4042db8ce16196fe0cd6c50b8cac6b13e770c22d958a89f1
Confidence: High