Analyze your own packages withvet GitHub

@evg-ui/lib@99.9.0

Suspicious
Analyzed at:6/10/2025, 4:39:11 PM
Source:https://registry.npmjs.org/@evg-ui/lib/-/lib-99.9.0.tgz
SHA256:1872c674fc1b8fe6d91df1205cb039a8079d7f8e9c51f56f3caaa3727fb79ac0
Confidence:Medium
Summary

This analysis was performed using vet and SafeDep Cloud Malicious Package Analysis. Integrate with GitHub using vet-action GitHub Action.

Malicious package. Executes hidden script during install to exfiltrate local IP, hostname, and homedir to an OAST server.

Details

The package includes a preinstall script that executes node test.js and redirects all output to /dev/null, hiding its execution. The test.js script exfiltrates sensitive information like local IP, hostname, and home directory to an OAST server (oastify.com) using DNS queries. This combination of a hidden preinstall script and data exfiltration strongly suggests malicious intent.