SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to data exfiltration via preinstall script, reading .npmrc, and sending data to a remote server. Few published versions.

Verification Record

The package is marked as malware by OSV: MAL-2026-2830 with source: amazon-inspector

Details

Note: This report is updated by a verification record

The package exhibits multiple strong indicators of malicious behavior. The preinstall script executes scripts/audit.js, which gathers sensitive information like username, hostname, git remote URL, Active Directory domain, DNS, and npm registry configuration. This information is then base64 encoded and sent to a remote server. This data exfiltration, combined with the suspicious use of a preinstall script and the limited number of published versions, strongly suggests malicious intent. The reading of .npmrc also raises concerns.

renovate-config-doctolib@9.9.16Malicious
Verified
Analysed at: 4/17/26, 6:20 AM
Source: https://registry.npmjs.org/renovate-config-doctolib/-/renovate-config-doctolib-9.9.16.tgz
SHA256: 2fbe07e97448d6dba6cc16489f03103338f3d1e06c644d853109b57d7d0042cf
Confidence: High