Open-source atomic malware analysis

Analyze another

shop-minis-2.0.5.tgz

TAR.GZ
Verdict: HOSTILE
Mal-ecule
O₄(Eu₂S₆Dy₂Xe)H₃(CmOsPo)Md₂(InPa₅)
Size 762 B download
First seen 23 days ago
Analyzed 23 days ago
Ecosystem javascript
Source npmjs.org

Objectives

suspicious severity, 75% confident.
exfiltration/dns Long subdomain encoding pattern
suspicious severity, 90% confident.
supply-chain/metadata-anomaly/manifest Package claims security research but runs install hooks
suspicious severity, 88% confident.
supply-chain/recon-exfil Tiny postinstall sidecar payload
notable severity, 90% confident.
discovery/system/fingerprint Collects operating system platform
notable severity, 100% confident.
execution/interpreter/script npm postinstall hook present
notable severity, 85% confident.
exfiltration/oob Oastify OOB service
notable severity, 90% confident.
supply-chain/hidden-payload Postinstall runs local node loader
notable severity, 85% confident.
supply-chain/install-hook/scripts Has postinstall script hook
notable severity, 85% confident.
supply-chain/metadata-anomaly/registry Registry metadata postinstall runs node script
notable severity, 97% confident.
supply-chain/trojanized/app Obfuscated dropper with exfiltration

Micro-behaviors

notable severity, 70% confident.
communications/http/request Node.js https.get
notable severity, 75% confident.
os/sysinfo os.hostname() call
notable severity, 100% confident.
process/create/shell Executes shell commands synchronously

Metadata

notable severity, 78% confident.
import require('https') import
notable severity, 70% confident.
package npm package missing license field
notable severity, 80% confident.
package/fields Package provides CLI binary
baseline severity, 100% confident.
lang Node.js shebang line
baseline severity, 100% confident.
lang/encoded JavaScript file basename

execution

notable severity, 90% confident.
script Script 'postinstall' executes node interpreter

supply-chain

notable severity, 80% confident.
install-hook Package has 'postinstall' hook that runs during install

20 of 38 traits shown

Identity

SHA-256 4be8db89785114ce9919d6d822f8363725890fa6cc2fa567a5fd73ee72854016
Filename shop-minis-2.0.5.tgz

Origin

Ecosystem javascript
Domain npmjs.org

Timeline

First seen 26 May 2026 11:26 UTC
Last analyzed 26 May 2026 12:17 UTC