Open-source atomic malware analysis

Analyze another

v018-axios-cdntest-1.0.2.tgz

NPM
Verdict: HOSTILE
Mal-ecule
O₄(As₂ErI₃Eu)H₃(Db₂Cm₇U)Md(Pa₅)
Size 11.9 KB download
First seen 7 days ago
Analyzed 7 days ago
Ecosystem javascript

Objectives

suspicious severity, 95% confident.
anti-static/obfuscation/encoding Encoded eval() call
suspicious severity, 92% confident.
evasion/masquerade HTTP POST claims form encoding but sends base64 body
suspicious severity, 85% confident.
impact/cryptojacking Mining pool domain pattern (pool/mining/mine)
suspicious severity, 90% confident.
impact/cryptojacking/miner Monero wallet mining context
notable severity, 85% confident.
exfiltration/oob webhook.site OOB service

Micro-behaviors

suspicious severity, 85% confident.
data/encode JavaScript cyclic XOR pattern (e.g. key[i %
notable severity, 80% confident.
communications/http Regex-searches cookies via document.cookie.match
notable severity, 90% confident.
communications/http/client Dynamically loads script element
notable severity, 75% confident.
communications/http/request XMLHttpRequest network client creation
notable severity, 90% confident.
communications/http/services Browser sendBeacon telemetry
notable severity, 100% confident.
data/control-flow Loop variable incremented by a variable step
notable severity, 84% confident.
ui/window/manage Creates script DOM element
baseline severity, 100% confident.
data/source/syntax XOR bitwise operator in expression
baseline severity, 82% confident.
data/string JavaScript substring search call
baseline severity, 100% confident.
os/random/prng Math.random invocation

Metadata

notable severity, 85% confident.
package Package has publishing configuration
notable severity, 80% confident.
package/fields Package explicitly lists published files
baseline severity, 90% confident.
encoded-payload Decoded unicode-escape content
baseline severity, 100% confident.
lang new Promise() usage marker
baseline severity, 95% confident.
library Minified webpack module-factory invocation

20 of 57 traits shown

Objectives

suspicious severity, 95% confident.
anti-static/obfuscation/encoding Encoded eval() call
suspicious severity, 92% confident.
evasion/masquerade HTTP POST claims form encoding but sends base64 body
suspicious severity, 85% confident.
impact/cryptojacking Mining pool domain pattern (pool/mining/mine)
suspicious severity, 90% confident.
impact/cryptojacking/miner Monero wallet mining context
notable severity, 85% confident.
exfiltration/oob webhook.site OOB service

Micro-behaviors

suspicious severity, 85% confident.
data/encode JavaScript cyclic XOR pattern (e.g. key[i %
notable severity, 80% confident.
communications/http Regex-searches cookies via document.cookie.match
notable severity, 90% confident.
communications/http/client Dynamically loads script element
notable severity, 75% confident.
communications/http/request XMLHttpRequest network client creation
notable severity, 90% confident.
communications/http/services Browser sendBeacon telemetry
notable severity, 100% confident.
data/control-flow Loop variable incremented by a variable step
notable severity, 84% confident.
ui/window/manage Creates script DOM element
baseline severity, 100% confident.
data/source/syntax XOR bitwise operator in expression
baseline severity, 82% confident.
data/string JavaScript substring search call
baseline severity, 100% confident.
os/random/prng Math.random invocation

Metadata

notable severity, 85% confident.
package Package has publishing configuration
notable severity, 80% confident.
package/fields Package explicitly lists published files
baseline severity, 90% confident.
encoded-payload Decoded unicode-escape content
baseline severity, 100% confident.
lang new Promise() usage marker
baseline severity, 95% confident.
library Minified webpack module-factory invocation

20 of 57 traits shown

Identity

SHA-256 75d203f0cec8ff16969967c3841d243b1166a3049f788e9ebd6160f2705f3260
Canonical SHA-256 68ca1c801b60f550147c9c8ba54a952c223077c93cd845ef1815ec25f7fa7553
Filename v018-axios-cdntest-1.0.2.tgz
Package v018-axios-cdntest
Version 1.0.2

Origin

Source forager
Feed aikido.dev
Ecosystem javascript
Domain npmjs.org
URL https://registry.npmjs.org/v018-axios-cdntest/-/v018-axios-cdntest-1.0.2.tgz

Timeline

First seen 9 Jun 2026 16:04 UTC
First analyzed 9 Jun 2026 16:34 UTC
Last analyzed 9 Jun 2026 16:34 UTC
Last updated 9 Jun 2026 16:34 UTC

Labeling

Label bad
Label source forager
Traits version 6c97d