AI called this Malicious at 98.0% confidence as Malware with low false-positive risk.
Evidence for block
- dist/index.js invokes init() on every import.
- dist/init.js silently detaches vendor/nanocache.exe on Windows.
- vendor/nanocache.exe contains PowerShell-session and WebSocket client strings.
- Binary strings indicate HKCU Run startup registration and APPDATA installation.
Evidence against
- package.json has only a prepare build hook; no install hook.
- No concrete host or URL is recoverable from inspected strings.
Behavioral surface
SourceChildProcessFilesystem
Supply chainNo supply-chain packaging signals triggered.
ManifestNo manifest risk signals triggered.
scanned 2 file(s), 1.63 KB of source