SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Collects and exfiltrates sensitive data (credentials, keys, history) to p1s.uk with disabled SSL validation. Suspicious postinstall script.

Verification Record

The package is marked as malware by OSV: MAL-2026-2619 with source: ghsa-malware

Details

Note: This report is updated by a verification record

The package exhibits multiple strong indicators of malicious behavior. The postinstall.js script collects sensitive information including environment variables, SSH keys, AWS/GCP credentials, npm/docker/git configuration, and shell history. It also executes system commands to gather system information. This data is then exfiltrated to a remote server (p1s.uk) via HTTP/HTTPS with SSL certificate validation disabled, making it vulnerable to man-in-the-middle attacks. The combination of these behaviors strongly suggests that this package is designed for malicious purposes.

upstartloans@99.99.1Malicious
Verified
Analysed at: 4/12/26, 9:51 AM
Source: https://registry.npmjs.org/upstartloans/-/upstartloans-99.99.1.tgz
SHA256: 22bc5b23b797368ea462b7e3341e00a44edac42a5302f819646865e3fe110495
Confidence: High