SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

The package is a malware. It exfiltrates system info to a hardcoded domain, collects sensitive data, and executes suspicious commands.

Verification Record

The package is marked as malware by OSV: MAL-2026-2615 with source: ghsa-malware

Details

Note: This report is updated by a verification record

The package contains a postinstall.js script that exhibits multiple malicious behaviors. It collects user, system, disk, and network information (Evidence 0), gathers and exfiltrates system information to a hardcoded domain p1s.uk (Evidence 1, 10), collects sensitive environment variables (Evidence 11), reads sensitive files such as SSH keys and shell history (Evidence 12, 4, 5, 6, 7, 8), and executes potentially dangerous commands (Evidence 13). The script also falls back to HTTP if HTTPS fails (Evidence 14). These behaviors, combined with YARA rule matches for system information exfiltration, SSH key access, and command execution, strongly suggest that the package is malicious.

upstartadmindashboard-@99.99.1Malicious
Verified
Analysed at: 4/12/26, 9:50 AM
Source: https://registry.npmjs.org/upstartadmindashboard-/-/upstartadmindashboard--99.99.1.tgz
SHA256: 553f76a9e2421236ecb30ef4dd81126d60601003e440e2f5a2a6f5f447b94f8d
Confidence: High