Malicious npm package executing base64-decoded shell command to download and run stage-2 payload from C2 server (89.36.224.5) targeting macOS
-= Per source details. Do not edit below this line.=-
The package @velora-dex/sdk was found to contain malicious code.
The OpenSSF Package Analysis project identified '@velora-dex/sdk' @ 9.4.1 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"source": "amazon-inspector",
"versions": [
"9.4.1"
],
"import_time": "2026-04-10T17:21:50.564186301Z",
"modified_time": "2026-04-10T17:02:58Z",
"sha256": "21a732dd2745098176d2c19fe3edb359db6f6690b5d14b8d49e8a00b61325311"
},
{
"source": "ossf-package-analysis",
"versions": [
"9.4.1"
],
"import_time": "2026-04-20T00:43:15.38090661Z",
"modified_time": "2026-04-07T19:23:02Z",
"sha256": "013b2c71633a40b8d425f998bb589074e403eea3069a0af42d70a041827475a3"
}
]
}