SafeDep
Install GitHub App
SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to sensitive data exfiltration via obfuscated preinstall script. Few published versions increase suspicion.

Verification Record

The package is marked as malware by OSV: MAL-2026-2829 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple strong indicators of malicious behavior. The preinstall script executes scripts/init.js, which exfiltrates sensitive information (username, hostname, git remote URL, AD domain, AD DNS, and npm registry configuration) to a remote server. The target host and path are obfuscated using base64 encoding, further concealing the malicious intent. The combination of sensitive data exfiltration, obfuscation, and execution during the preinstall phase strongly suggests that this package is malicious. The fact that the project has few published versions adds to the suspicion.

paddle-internal-scripts@9.9.16Malicious
Verified
Analysed at: 4/17/26, 6:19 AM
Source: https://registry.npmjs.org/paddle-internal-scripts/-/paddle-internal-scripts-9.9.16.tgz
SHA256: aa52068fdeb2a1085f558a02c7f1725673b3a1e3fc808fa19eb42695e7a47763
Confidence: High