SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Package exfiltrates user info to a remote server via wget in test, preinstall, and preupdate scripts. Very few published versions.

Verification Record

The package is marked as malware by OSV: MAL-2026-2636 with source: ghsa-malware

Details

Note: This report is updated by a verification record

The package contains suspicious scripts in package.json and package.json.save that exfiltrate sensitive information (username, current path, hostname) to a remote server (webhook.site) using wget during test, preinstall, and preupdate phases. This behavior is detected by both YARA rules (npm_preinstall_command, npm_fetcher) and LLM-based analysis, indicating a high likelihood of malicious intent. The project also has very few published versions, further increasing suspicion.

seaport-core-16@8.0.0Malicious
Verified
Analysed at: 4/13/26, 6:13 AM
Source: https://registry.npmjs.org/seaport-core-16/-/seaport-core-16-8.0.0.tgz
SHA256: 06cae350bbfb428eacea4cc748686260589c78358d2629437a7ecec40fba50f2
Confidence: High