Mal-ecule
O₄(As₂ErI₃Eu)H₃(Db₂Cm₇U)Md(Pa₅)
Objectives
suspicious severity, 95% confident.
anti-static/obfuscation/encoding
Encoded eval() call
suspicious severity, 92% confident.
evasion/masquerade
HTTP POST claims form encoding but sends base64 body
suspicious severity, 85% confident.
impact/cryptojacking
Mining pool domain pattern (pool/mining/mine)
suspicious severity, 90% confident.
impact/cryptojacking/miner
Monero wallet mining context
notable severity, 85% confident.
exfiltration/oob
webhook.site OOB service
Micro-behaviors
suspicious severity, 85% confident.
data/encode
JavaScript cyclic XOR pattern (e.g. key[i %
notable severity, 80% confident.
communications/http
Regex-searches cookies via document.cookie.match
notable severity, 90% confident.
communications/http/client
Dynamically loads script element
notable severity, 75% confident.
communications/http/request
XMLHttpRequest network client creation
notable severity, 90% confident.
communications/http/services
Browser sendBeacon telemetry
notable severity, 100% confident.
data/control-flow
Loop variable incremented by a variable step
notable severity, 84% confident.
ui/window/manage
Creates script DOM element
baseline severity, 100% confident.
data/source/syntax
XOR bitwise operator in expression
baseline severity, 82% confident.
data/string
JavaScript substring search call
baseline severity, 100% confident.
os/random/prng
Math.random invocation
Metadata
notable severity, 85% confident.
package
Package has publishing configuration
notable severity, 80% confident.
package/fields
Package explicitly lists published files
baseline severity, 90% confident.
encoded-payload
Decoded unicode-escape content
baseline severity, 100% confident.
lang
new Promise() usage marker
baseline severity, 95% confident.
library
Minified webpack module-factory invocation
20 of 57 traits shown
Objectives
suspicious severity, 95% confident.
anti-static/obfuscation/encoding
Encoded eval() call
suspicious severity, 92% confident.
evasion/masquerade
HTTP POST claims form encoding but sends base64 body
suspicious severity, 85% confident.
impact/cryptojacking
Mining pool domain pattern (pool/mining/mine)
suspicious severity, 90% confident.
impact/cryptojacking/miner
Monero wallet mining context
notable severity, 85% confident.
exfiltration/oob
webhook.site OOB service
Micro-behaviors
suspicious severity, 85% confident.
data/encode
JavaScript cyclic XOR pattern (e.g. key[i %
notable severity, 80% confident.
communications/http
Regex-searches cookies via document.cookie.match
notable severity, 90% confident.
communications/http/client
Dynamically loads script element
notable severity, 75% confident.
communications/http/request
XMLHttpRequest network client creation
notable severity, 90% confident.
communications/http/services
Browser sendBeacon telemetry
notable severity, 100% confident.
data/control-flow
Loop variable incremented by a variable step
notable severity, 84% confident.
ui/window/manage
Creates script DOM element
baseline severity, 100% confident.
data/source/syntax
XOR bitwise operator in expression
baseline severity, 82% confident.
data/string
JavaScript substring search call
baseline severity, 100% confident.
os/random/prng
Math.random invocation
Metadata
notable severity, 85% confident.
package
Package has publishing configuration
notable severity, 80% confident.
package/fields
Package explicitly lists published files
baseline severity, 90% confident.
encoded-payload
Decoded unicode-escape content
baseline severity, 100% confident.
lang
new Promise() usage marker
baseline severity, 95% confident.
library
Minified webpack module-factory invocation
20 of 57 traits shown
Identity
| SHA-256 | 75d203f0cec8ff16969967c3841d243b1166a3049f788e9ebd6160f2705f3260 |
|---|---|
| Canonical SHA-256 | 68ca1c801b60f550147c9c8ba54a952c223077c93cd845ef1815ec25f7fa7553 |
| Filename | v018-axios-cdntest-1.0.2.tgz |
| Package | v018-axios-cdntest |
| Version | 1.0.2 |
Origin
| Source | forager |
|---|---|
| Feed | aikido.dev |
| Ecosystem | javascript |
| Domain | npmjs.org |
| URL | https://registry.npmjs.org/v018-axios-cdntest/-/v018-axios-cdntest-1.0.2.tgz |
Timeline
| First seen | 9 Jun 2026 16:04 UTC |
|---|---|
| First analyzed | 9 Jun 2026 16:34 UTC |
| Last analyzed | 9 Jun 2026 16:34 UTC |
| Last updated | 9 Jun 2026 16:34 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | forager |
| Traits version | 6c97d |
Not seeing what you expected? Let us know