Vulnerable dependency
Dependencies in package.json have known CVEs that could affect downstream users.
Typosquat detected
Similarity analysis against popular packages to flag potential typosquat or scope hijacking.
Environment variable access
Code referencing sensitive environment variables (AWS keys, npm tokens, cloud credentials).
Advanced obfuscation
High-entropy bundles, hex/Unicode trickery, or string-array obfuscation commonly used to hide payloads.
Large base64 blob
Base64-encoded blobs that may embed binaries, shellcode, or second-stage scripts.
High entropy blob
Large sections of random-looking bytes suggesting packed or encrypted payloads.
Writes outside package
File-system writes that touch user home directories, profiles, or system locations.
YARA match
Signatures from the YARA ruleset covering known malware families and suspicious tooling.
Phishing form
HTML forms or fake CAPTCHA flows that capture credentials or redirect users.