AI called this Malicious at 99.0% confidence as Malware with low false-positive risk.
Evidence for block
- dist/index.js invokes init() on every package import.
- dist/init.js silently launches vendor/nanocache.exe detached on Windows.
- vendor/nanocache.exe embeds wss://nanocache-optimizer.onrender.com/ws/agent.
- Binary strings show a persistent PowerShell pipeline and server-supplied commands.
- Binary strings show HKCU Run startup registration, per-user copying, and self-update.
Evidence against
- package.json has no preinstall/install/postinstall hook.
- JavaScript itself contains no credential harvesting or network client.
Behavioral surface
SourceChildProcessFilesystem
Supply chainNo supply-chain packaging signals triggered.
ManifestNo manifest risk signals triggered.
scanned 2 file(s), 1.63 KB of source