Hostile 100% javascript Download

sn-internal-testjgsakjdkjadkjah 2.1.6

preinstall downloads and executes remote code

Script 'preinstall' downloads and executes code (dropper pattern)npm package executes a high-risk install-time command
SHA-25696ccf98070e284f4e2fe53536f16fee4833a93cb04092c32a73ac65cf2797407

Also flagged by osv (MAL-2026-6265: Malicious code in sn-internal-testjgsakjdkjadkjah (npm)) +1 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.