Security Findings
13Obfuscated execution
MaliciousScannerRuntime-assembled code executed (assembled from file fragments)
Hardcoded C2 infrastructure3×
SuspiciousScannerHardcoded public IP address: 17.13.5.15
Hardcoded public IP address: 17.3.3.30
Hardcoded public IP address: 4.4.17.1
Publisher cannot be tied to the declared repo
SuspiciousLineageThe declared source repository could not be tied to this publisher: the registry namespace does not match the repo owner, the namespace is not verified, and no Marketplace twin corroborates it. Repo lineage is not shown, because it would describe a repository this publisher may not own.
Suspicious outbound hosts8×
SuspiciousScannerOutbound URLs to non-allowlisted host(s): api.www.myobfuscate.com, blog.izs.me, domain.com, domenicdenicola.com, dominictarr.com, donavon.com, esprima.org, jsbeautifier.org
Outbound URLs to non-allowlisted host(s): allyoucanleet.com, bugs.webkit.org, dojofoundation.org, domain.com, ecma-international.org, eligrey.com, fgribreau.com, jquery.org
Outbound URLs to non-allowlisted host(s): dom.spec.whatwg.org, feross.org, goo.gl, html.spec.whatwg.org, infra.spec.whatwg.org, mathiasbynens.be, purl.oclc.org, schemas.openxmlformats.org
Outbound URLs to non-allowlisted host(s): blog.izs.me, example.net, schemas.openxmlformats.org, schemas.zwobble.org, stackoverflow.com, substack.net, zlib.net
Outbound URLs to non-allowlisted host(s): alexei.ro, blog.izs.me, domenic.me, domenicdenicola.com, donavon.com, feross.org, jeditoolkit.com, jsperf.com
Outbound URLs to non-allowlisted host(s): creativecommons.org, dojofoundation.org, jquery.org, purl.org, schemas.openxmlformats.org, schemas.zwobble.org, underscorejs.org
Outbound URLs to non-allowlisted host(s): gruntjs.com, identi.ca, mathiasbynens.be, twitter.com, www.csail.mit.edu, www.ercim.org, www.gnu.org, www.keio.ac.jp
Outbound URLs to non-allowlisted host(s): dom.spec.whatwg.org, feross.org, goo.gl, html.spec.whatwg.org, infra.spec.whatwg.org, opensource.org, tc39.es, tools.ietf.org