Mal-ecule
O(S)H(Po)Md(Pa₇)
Objectives
notable severity, 70% confident.
supply-chain/metadata-anomaly/dependency
npm package has prepublishOnly hook
baseline severity, 90% confident.
anti-static/obfuscation/code-metrics
Extremely high embedded code count
baseline severity, 90% confident.
execution/autoinstall
yarn command mentioned in source comment
baseline severity, 90% confident.
supply-chain/trojanized/app
Benign bundled or test obfuscation context
component severity, 100% confident.
anti-static/obfuscation/payload
Source map file extension
component severity, 100% confident.
anti-static/obfuscation/string
JavaScript minified or map basename
Micro-behaviors
notable severity, 85% confident.
process/interpreter
npm script runs a script interpreter
baseline severity, 100% confident.
data/control-flow
Loop structure
baseline severity, 100% confident.
data/encode
Substring call
baseline severity, 90% confident.
data/encode/permutation
Nested for loops (control-flow building block)
baseline severity, 82% confident.
data/string
JavaScript substring search call
baseline severity, 80% confident.
data/text
English language detection
component severity, 100% confident.
data/text/keywords
Destructive action verb
Metadata
notable severity, 90% confident.
package
Package has TypeScript support
notable severity, 90% confident.
package/fields
Package has TypeScript types entry
baseline severity, 85% confident.
file/text
High function density
baseline severity, 100% confident.
lang
Embedded source-map sourcesContent array
baseline severity, 100% confident.
library
JavaScript module exports
baseline severity, 90% confident.
package/testing/harness
Identifies Node.js test files
baseline severity, 95% confident.
package/testing/presence
File in test fixture or helper directory
20 of 47 traits shown
Identity
| SHA-256 | 7f8fc8d3541e0c4273db5f4460b543ffcfc5b7b5a3b7fc1742d7eaf276b98ae1 |
|---|---|
| Canonical SHA-256 | 05d0b42cd805a15f4980101009923029f26b8f4a3ecd65972cb6b5fac36879ab |
| Filename | @poker-apprentice-hand-evaluator-4.2.0.tgz |
| Package | @poker-apprentice/hand-evaluator |
Origin
| Source | forager |
|---|---|
| Feed | npmjs.org |
| Ecosystem | javascript |
| Domain | npmjs.org |
| URL | https://registry.npmjs.org/@poker-apprentice/hand-evaluator/-/hand-evaluator-4.2.0.tgz |
Timeline
| First seen | 13 Jun 2026 22:10 UTC |
|---|---|
| First analyzed | 13 Jun 2026 22:45 UTC |
| Last analyzed | 13 Jun 2026 22:45 UTC |
| Last updated | 13 Jun 2026 22:45 UTC |
Labeling
| Label | unknown |
|---|---|
| Label source | forager |
| Traits version | c7b65 |
Not seeing what you expected? Let us know