AI called this Malicious at 98.0% confidence as Malware with low false-positive risk.
Evidence for block
- dist/index.js autostarts a bundled executable on import.
- The child is detached, hidden, stdio-ignored, and unref'd.
- The executable receives the full parent environment.
- vendor/nanocache.exe embeds a screen-monitoring WebSocket endpoint.
- PE imports include screen capture and WinHTTP/WebSocket APIs.
Evidence against
- package.json has no install lifecycle hook.
- No JavaScript network client or filesystem harvesting was found.
Behavioral surface
SourceChildProcessEnvironmentVarsFilesystemShell
Supply chainNo supply-chain packaging signals triggered.
ManifestNo manifest risk signals triggered.
scanned 2 file(s), 15.0 KB of source