AI called this Clean at 99.0% confidence as Benign with low false-positive risk.
Evidence for block
- README.md states this is a security holding package for a previously removed malicious release.
Evidence against
- package.json contains only name, version, description, and repository metadata.
- package.json has no lifecycle scripts, entrypoints, binaries, dependencies, or install hooks.
- Package contents contain only package.json and README.md; no executable source, payload, or binary exists.
- No network endpoint, file mutation, credential access, dynamic execution, or persistence mechanism is present.
Behavioral surface
SourceNo risky source behavior triggered.
Supply chainNo supply-chain packaging signals triggered.
scanned 0 file(s), 0 B of source