SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Package is malware due to data exfiltration to multiple domains via DNS and HTTPS, along with a suspicious preinstall script.

Verification Record

The package is marked as malware by OSV: MAL-2026-2654 with source: ghsa-malware

Details

Note: This report is updated by a verification record

The package exhibits multiple strong indicators of malicious behavior. The index.js file contains code that collects sensitive system information (hostname, username, OS details, environment variables) and exfiltrates it to ienfcixqbgvbxkccdoxgfz2zhmspdpiys.oast.fun and www.mygoals.live via HTTPS POST requests and DNS resolution, as highlighted by multiple YARA rules and LLM analysis. The package.json file includes a preinstall script that executes node index.js, enabling code execution during installation. This combination of data exfiltration and preinstall script execution strongly suggests malicious intent.

pinstatsd@99.0.0Malicious
Verified
Analysed at: 4/11/26, 5:51 PM
Source: https://registry.npmjs.org/pinstatsd/-/pinstatsd-99.0.0.tgz
SHA256: 4f09b9ae0b8a8f1e96092f55a3d2c6ab1ca7e0c6a63d5fd793ced0a4cf3cec22
Confidence: High