Open-source atomic malware analysis

Analyze another

lodash.words 3.2.0

UNKNOWN
Verdict: BENIGN
“The lodash method `_.words` exported as a module.”
Mal-ecule
H(Db)Md₂(Pa₂)
Size 3.5 KB download
First seen 7 days ago
Analyzed 21 hours ago
Ecosystem javascript

Referenced by 2 samples

Well-known

baseline severity, 90% confident.
lib/core Lodash modular source member marker

Objectives

component severity, 80% confident.
supply-chain/install-hook/package Repository uses GitHub shorthand format

Micro-behaviors

notable severity, 90% confident.
data/string Dense concatenated string fragments

Metadata

notable severity, 99% confident.
file/profile Escaped Unicode codepoint in source
notable severity, 90% confident.
package/manifest Repository uses owner/project coordinate
baseline severity, 100% confident.
package package.json defines a package version
baseline severity, 95% confident.
package/files Manifest sits at npm publish root
baseline severity, 100% confident.
package/quality package.json defines a package name
component severity, 100% confident.
file/extension JavaScript source filename extension

Identity

SHA-256 161cd0a0df64d7077d0c40dec36e1dc3cf448edd0404b5be571eea7cfa4dacde
Filename [email protected]
Package lodash.words
Version 3.2.0
PURL pkg:npm/[email protected]

Origin

Source x
Feed ossf-malicious-packages
Ecosystem javascript
Domain npmjs.org
URL https://registry.npmjs.org/lodash.words/-/lodash.words-3.2.0.tgz

Timeline

First seen 18 Aug 2026 08:18 UTC
First analyzed 18 Aug 2026 08:19 UTC
Last analyzed 24 Aug 2026 13:02 UTC
Last updated 24 Aug 2026 13:07 UTC

Labeling

Label unknown
Traits version 18b13