Hostile 100% javascript Download

mediapipe 1.2.9

Exfiltrates system credentials and files

Hollow npm package shell-exfils local file contentNode shell curl file exfiltration
SHA-256cb406254df620827a02141b38f3cbd4a85d49058cdb1e3ea8b3eee29a6da8144

Also flagged by osv (MAL-2025-48527: Malicious code in mediapipe (npm)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.