Mal-ecule
O₄(Eu₂S₆Dy₂Xe)H₃(CmOsPo)Md₂(InPa₅)
Objectives
suspicious severity, 75% confident.
exfiltration/dns
Long subdomain encoding pattern
suspicious severity, 90% confident.
supply-chain/metadata-anomaly/manifest
Package claims security research but runs install hooks
suspicious severity, 88% confident.
supply-chain/recon-exfil
Tiny postinstall sidecar payload
notable severity, 90% confident.
discovery/system/fingerprint
Collects operating system platform
notable severity, 100% confident.
execution/interpreter/script
npm postinstall hook present
notable severity, 85% confident.
exfiltration/oob
Oastify OOB service
notable severity, 90% confident.
supply-chain/hidden-payload
Postinstall runs local node loader
notable severity, 85% confident.
supply-chain/install-hook/scripts
Has postinstall script hook
notable severity, 85% confident.
supply-chain/metadata-anomaly/registry
Registry metadata postinstall runs node script
notable severity, 97% confident.
supply-chain/trojanized/app
Obfuscated dropper with exfiltration
Micro-behaviors
notable severity, 70% confident.
communications/http/request
Node.js https.get
notable severity, 75% confident.
os/sysinfo
os.hostname() call
notable severity, 100% confident.
process/create/shell
Executes shell commands synchronously
Metadata
notable severity, 78% confident.
import
require('https') import
notable severity, 70% confident.
package
npm package missing license field
notable severity, 80% confident.
package/fields
Package provides CLI binary
baseline severity, 100% confident.
lang
Node.js shebang line
baseline severity, 100% confident.
lang/encoded
JavaScript file basename
execution
notable severity, 90% confident.
script
Script 'postinstall' executes node interpreter
supply-chain
notable severity, 80% confident.
install-hook
Package has 'postinstall' hook that runs during install
20 of 38 traits shown
Identity
| SHA-256 | 4be8db89785114ce9919d6d822f8363725890fa6cc2fa567a5fd73ee72854016 |
|---|---|
| Filename | shop-minis-2.0.5.tgz |
Origin
| Ecosystem | javascript |
|---|---|
| Domain | npmjs.org |
Timeline
| First seen | 26 May 2026 11:26 UTC |
|---|---|
| Last analyzed | 26 May 2026 12:17 UTC |
Not seeing what you expected? Let us know