SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Package is malware. It steals credentials, collects system info, and exfiltrates data to a remote server via postinstall script.

Verification Record

The package is marked as malware by OSV: MAL-2026-2611 with source: ghsa-malware

Details

Note: This report is updated by a verification record

The package upstart-lending-status version 99.99.1 is highly likely to be malware. Multiple YARA rules and LLM-based analysis of postinstall.js show strong evidence of malicious behavior. Specifically, the script accesses bash and zsh history, SSH private keys, and GCP credentials. It also collects user, system, disk, and network information, and attempts to exfiltrate this data to a remote server (p1s.uk) using both HTTPS and HTTP. The package.json contains a postinstall script that executes node postinstall.js upon installation, which is a common malware technique. Finally, the project has only one published version, which can be a sign of malicious intent. The combination of these factors strongly suggests that this package is malicious.

upstart-lending-status@99.99.1Malicious
Verified
Analysed at: 4/12/26, 10:45 AM
Source: https://registry.npmjs.org/upstart-lending-status/-/upstart-lending-status-99.99.1.tgz
SHA256: 8f2f0b0e6cdcc210e750afe541ab7031d586efc999b24caafd4d967db96ea015
Confidence: High