Open-source atomic malware analysis

Analyze another

postinstall.js

JAVASCRIPT
Verdict: HOSTILE
Mal-ecule
KO₄(CaS₄Dy₂As₂)H(Db)Md(Pa₂)
Size 568 B download
First seen 118 days ago
Analyzed 118 days ago
Ecosystem malcontent-samples

Well-known

notable severity, 80% confident.
malware/stealer CursedGrabber postinstall variable name

Objectives

hostile severity, 100% confident.
credential-access/discord/token CursedGrabber Discord token stealer family
hostile severity, 98% confident.
supply-chain/hidden-payload NPM supply chain stealer package
notable severity, 80% confident.
discovery os.homedir() user home directory
notable severity, 85% confident.
discovery/system/fingerprint Collects user home directory path
notable severity, 90% confident.
supply-chain/install-hook File named postinstall.js (npm hook)
notable severity, 88% confident.
supply-chain/recon-exfil Tiny postinstall sidecar payload
component severity, 100% confident.
anti-static/obfuscation JavaScript/TypeScript file extension
component severity, 70% confident.
supply-chain/metadata-anomaly/markers Small file under 5KB

Micro-behaviors

baseline severity, 80% confident.
process Accesses process.argv (Command line arguments)
component severity, 75% confident.
data/text Stealer keyword

Metadata

baseline severity, 100% confident.
lang/encoded JavaScript file basename
baseline severity, 85% confident.
package::terser-output Terser/UglifyJS minified output markers
component severity, 80% confident.
package Short sidecar-sized source

Identity

SHA-256 64f932df8e6f02eadafe3b629cd974c4577521c430cf4f576b0b5022dc8b0db9
Filename postinstall.js

Origin

Source harvest
Feed datasets
Ecosystem malcontent-samples

Timeline

First seen 24 Apr 2026 16:18 UTC
Last analyzed 24 Apr 2026 17:17 UTC
Last updated 24 Apr 2026 17:17 UTC

Labeling

Label bad
Label source harvest
Traits version 8bf61