Open-source atomic malware analysis

Analyze another

@poker-apprentice-hand-evaluator-4.2.0.tgz

NPM
Verdict: BENIGN
Mal-ecule
O(S)H(Po)Md(Pa₇)
Size 458.2 KB download
First seen 8 days ago
Analyzed 8 days ago
Ecosystem javascript

Objectives

notable severity, 70% confident.
supply-chain/metadata-anomaly/dependency npm package has prepublishOnly hook
baseline severity, 90% confident.
anti-static/obfuscation/code-metrics Extremely high embedded code count
baseline severity, 90% confident.
execution/autoinstall yarn command mentioned in source comment
baseline severity, 90% confident.
supply-chain/trojanized/app Benign bundled or test obfuscation context
component severity, 100% confident.
anti-static/obfuscation/payload Source map file extension
component severity, 100% confident.
anti-static/obfuscation/string JavaScript minified or map basename

Micro-behaviors

notable severity, 85% confident.
process/interpreter npm script runs a script interpreter
baseline severity, 100% confident.
data/control-flow Loop structure
baseline severity, 100% confident.
data/encode Substring call
baseline severity, 90% confident.
data/encode/permutation Nested for loops (control-flow building block)
baseline severity, 82% confident.
data/string JavaScript substring search call
baseline severity, 80% confident.
data/text English language detection
component severity, 100% confident.
data/text/keywords Destructive action verb

Metadata

notable severity, 90% confident.
package Package has TypeScript support
notable severity, 90% confident.
package/fields Package has TypeScript types entry
baseline severity, 85% confident.
file/text High function density
baseline severity, 100% confident.
lang Embedded source-map sourcesContent array
baseline severity, 100% confident.
library JavaScript module exports
baseline severity, 90% confident.
package/testing/harness Identifies Node.js test files
baseline severity, 95% confident.
package/testing/presence File in test fixture or helper directory

20 of 47 traits shown

Identity

SHA-256 7f8fc8d3541e0c4273db5f4460b543ffcfc5b7b5a3b7fc1742d7eaf276b98ae1
Canonical SHA-256 05d0b42cd805a15f4980101009923029f26b8f4a3ecd65972cb6b5fac36879ab
Filename @poker-apprentice-hand-evaluator-4.2.0.tgz
Package @poker-apprentice/hand-evaluator

Origin

Source forager
Feed npmjs.org
Ecosystem javascript
Domain npmjs.org
URL https://registry.npmjs.org/@poker-apprentice/hand-evaluator/-/hand-evaluator-4.2.0.tgz

Timeline

First seen 13 Jun 2026 22:10 UTC
First analyzed 13 Jun 2026 22:45 UTC
Last analyzed 13 Jun 2026 22:45 UTC
Last updated 13 Jun 2026 22:45 UTC

Labeling

Label unknown
Label source forager
Traits version c7b65