Note: This report is updated by a verification record
The package is likely malware due to data exfiltration, arbitrary command execution in preinstall script, and a single published version.
The package is marked as malware by OSV: MAL-2026-2505 with source: amazon-inspector
Note: This report is updated by a verification record
The package exhibits multiple suspicious behaviors indicating it is likely malware. The preinstall.js script exfiltrates data (hostname and git email) to an external server and executes arbitrary commands using execSync. The package.json file defines a preinstall script that executes preinstall.js, which is a common malware technique. The project has only one published version, making it less trustworthy. These factors combined strongly suggest malicious intent.