Analyze your own packages withvet GitHub

natel-plotly-panel@1.0.1

Suspicious
Analyzed at:6/28/2025, 1:03:00 PM
Source:https://registry.npmjs.org/natel-plotly-panel/-/natel-plotly-panel-1.0.1.tgz
SHA256:a9a2042bab3e5f7c3526327a33780f829822ac9e7129161dac1a5eafa371ee5a
Confidence:Medium
Summary

This analysis was performed using vet and SafeDep Cloud Malicious Package Analysis. Integrate with GitHub using vet-action GitHub Action.

Malicious package due to suspicious preinstall, preupdate, and test scripts downloading and executing code from a remote server.

Details

The package contains suspicious preinstall, preupdate, and test scripts in pakage.json that download and execute code from a remote server (oastify.com). This allows for arbitrary code execution and exfiltration of sensitive information (username, path, hostname) during installation, update, and testing, indicating malicious intent.