SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Collects system info, reads sensitive files, and exfiltrates data to a suspicious host. Multiple YARA matches confirm malicious intent.

Verification Record

The package is marked as malware by OSV: MAL-2026-2620 with source: ghsa-malware

Details

Note: This report is updated by a verification record

The package exhibits multiple strong indicators of malicious behavior. The postinstall.js script collects extensive system information, including sensitive files (SSH keys, .env files), environment variables (potential secrets, API keys), and command outputs. This data is then exfiltrated to a suspicious callback host p1s.uk via HTTPS (with a fallback to insecure HTTP). Multiple YARA rules confirm these behaviors, including accessing bash/zsh history, SSH keys, GCP credentials, and exfiltrating system information. The combination of these factors strongly suggests that this package is designed for malicious purposes, specifically data theft and system reconnaissance.

upstartportal@99.99.1Malicious
Verified
Analysed at: 4/12/26, 9:51 AM
Source: https://registry.npmjs.org/upstartportal/-/upstartportal-99.99.1.tgz
SHA256: 9f4655d7e9636b6f59619136d7b45a1c8e0e3ef641cb378116b1df6a2ed2a6be
Confidence: High