OpenSSF/OSV advisory MAL-2026-17296 confirms this npm version as malicious. The tarball contains only package.json and an 8.4 MB Go-compiled Windows executable, Kelimasow.exe (sha256 875c7641dc980538f3c3d8b344d173f97cf64a5d97dcf88d8e2932c83b876b92). package.json declares scripts.postinstall = "Kelimasow.exe", so npm install auto-executes this binary on any Windows host. The package has no library code (main points at a nonexistent index.js), no README, no source, no build system, and empty...
This report applies to test-agency-assignment-01@1.0.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.