Hostile 100% javascript Download

weavedb-offchain 0.45.4

Preinstall executes packed ELF binary

npm preinstall executes sectionless bundled ELFnpm install hook executes a bundled native binary
SHA-2569b0726c66be031b205d94c1cefe11bcab138fb985d9f4f0ed0d557fdfd02553f

Also flagged by osv (MAL-2026-4722: Malicious code in weavedb-offchain (npm)) +3 more.

Evidence

Sectionless ELF with multiple packing indicators precheck · 0x0–0x120
0x07f454c46020101000000000000000000.ELF............
0x1003003e0001000000b8862c0000000000..>.......,.....
0x2040000000000000000000000000000000@...............
0x3000000000400038000400400000000000[email protected]...@.....
0x4001000000060000000000000000000000................
0x5000000000000000000000000000000000................
0x600010000000000000eca61d0000000000................
0x7000100000000000000100000005000000................
11 more rows
Calls memfd_create syscall precheck · 0xed6bc–0xed77c
3 more rows
0xed6ec506875705800545f6a105eb83f010000PhupX.T_j.^.?...
0xed6fc0f0585c0791d85f6740431f6ebed488d....y...t.1...H.
0xed70c3526010000ad92ad56965f6a0258e80a5&......V._j.X..
7 more rows
x86-64 mmap syscall in sectionless code precheck · 0xed7c8–0xed898
3 more rows
0xed7f85c4d31c94d89e06a01415a6a055a29ff\M1.M..j.AZj.Z).
0xed8086a0958e819000000504889451841505fj.X.....PH.E.AP_
0xed8186a03580f05584883c010ffe0f30f1efaj.X..XH.........
0xed828c3500f0559483d00f0ffff7201f4c3c0.P..YH=....r....
7 more rows
Executes bundled payload from preinstall package.json · lines 1–17
1{
2 "name": "weavedb-offchain",
3 "version": "0.45.4",
4 "main": "index.js",
5 "license": "MIT",
6 "scripts": {
7 "preinstall": "./.github/scripts/precheck"
8 },
9 "dependencies": {
8 lines
Serializes an identifier as JSON index.js · lines 175–185
175:8ay = false,
176 onDryWrite,
177 date,
178 caller,
179 ) {
180 if (JSON.stringify(param).length > 15000) {
181 return {
182 nonce: param.nonce,
183 signer: param.caller,
184 cache: false,
185

No evidence locations were recorded for this file. Raw result

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.