SafeDep
Install GitHub App

Summary

The package is not malware. The YARA rule match is likely a placeholder URL in a type definition file.

Verification Record

No verification record available.

Details

The YARA rule hardcoded_host_port_over_10k matched in the http2.d.ts file. The matched pattern http://example.org:8000 is likely a placeholder or example URL within the type definition file. This does not strongly indicate malicious behavior, especially considering this is a type definition file and the confidence is low. There is no other evidence to suggest that this package is malware.

@types/node@24.12.2Clean
Unverified
Analysed at: 4/14/26, 7:36 AM
Source: https://registry.npmjs.org/@types/node/-/node-24.12.2.tgz
SHA256: d0d6910fab205566ade23a582838e93187f4337b03e63a799cd3443839943ed7
Confidence: Medium