SafeDep
Install GitHub App
SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

The package is likely malware due to data exfiltration, arbitrary command execution in preinstall script, and a single published version.

Verification Record

The package is marked as malware by OSV: MAL-2026-2505 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors indicating it is likely malware. The preinstall.js script exfiltrates data (hostname and git email) to an external server and executes arbitrary commands using execSync. The package.json file defines a preinstall script that executes preinstall.js, which is a common malware technique. The project has only one published version, making it less trustworthy. These factors combined strongly suggest malicious intent.

@aspect-security/argon2@1.0.1Malicious
Verified
Analysed at: 4/7/26, 12:16 PM
Source: https://registry.npmjs.org/@aspect-security/argon2/-/argon2-1.0.1.tgz
SHA256: 21e2b89d19e81a15cf6e743272038dbb1c2f0648734698acf50633c92e1bf93b
Confidence: High