Open-source atomic malware analysis

Analyze another

espree 5.0.1

UNKNOWN
Verdict: BENIGN
“An Esprima-compatible JavaScript parser built on Acorn”
Mal-ecule
H₂(CmPo)Md₂(Pa₂)
Size 17.8 KB download
First seen 15 days ago
Analyzed 5 days ago
Ecosystem javascript

Referenced by 10 samples

Objectives

component severity, 80% confident.
supply-chain/install-hook/package Repository uses GitHub shorthand format

Micro-behaviors

notable severity, 90% confident.
communications/http/url References a public code-forge URL
notable severity, 85% confident.
process/interpreter Package script invokes a language interpreter
baseline severity, 80% confident.
data/source/syntax Reads an array element into a variable
component severity, 90% confident.
data/control-flow Top-level non-require string call

Metadata

notable severity, 90% confident.
file Several Base64-looking strings in source
notable severity, 92% confident.
package/files Package.json declares a files allowlist
notable severity, 90% confident.
package/manifest Repository uses owner/project coordinate
baseline severity, 100% confident.
package package.json defines a package version
baseline severity, 100% confident.
package/quality package.json defines a package name
component severity, 100% confident.
lang References the JavaScript .length property
component severity, 70% confident.
package/dependencies npm manifest has many devDependencies

Identity

SHA-256 84f0bc12d4e6f1770c1fd1927a28d5893a328195cfa7dcbf707a6b5750ce678c
Canonical SHA-256 64107390af1155ff6e64094f74a6cf195226c3938dda73bd0399a85eb193594c
Filename [email protected]
Package espree
Version 5.0.1
PURL pkg:npm/[email protected]

Origin

Source x
Feed pkg.go.dev
Ecosystem javascript
Domain npmjs.org
URL https://registry.npmjs.org/espree/-/espree-5.0.1.tgz

Timeline

First seen 10 Aug 2026 17:24 UTC
First analyzed 10 Aug 2026 17:20 UTC
Last analyzed 21 Aug 2026 02:36 UTC
Last updated 21 Aug 2026 02:39 UTC

Labeling

Label unknown
Traits version efa45