SafeDep
Install GitHub App

Summary

Suspicious findings, including a hardcoded IP and high entropy in images, are not conclusive enough to classify as malware.

Verification Record

No verification record available.

Details

The evidence includes a hardcoded IP address and port, which could be indicative of malicious activity, but it's also possible it's being used for legitimate proxy purposes. The other pieces of evidence, such as file extension mismatches and high entropy in image files, are suspicious but not conclusive evidence of malware. High entropy in images might indicate steganography or obfuscation, but without further analysis, it's difficult to determine the intent. Given the low confidence of the YARA rule matches and the possibility of legitimate use cases, I cannot classify this package as malware.

NeteaseCloudMusicApi@4.31.0Clean
Unverified
Analysed at: 4/14/26, 6:33 AM
Source: https://registry.npmjs.org/NeteaseCloudMusicApi/-/NeteaseCloudMusicApi-4.31.0.tgz
SHA256: eff104490fd430ae2ded075bcf1a0c0b7f3fdace7c9e6b2109533449c269bf66
Confidence: Medium