An npm package started as a legitimate XML-RPC implementation, received 16 genuine updates over a year, then evolved to include cryptomining and SSH key theft every 12 hours. By escalating malicious behavior gradually, it evaded detection for over a year. 68 systems confirmed compromised.
PACKAGE_ACTIVE_MALWARE eventually; behavioral drift over 1 year is hard to catch proactively
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Partial | PACKAGE_ACTIVE_MALWARE eventually; behavioral drift over 1 year is hard to catch proactively |
| Socket | Partial | Gradual behavioral escalation over 1 year may evade point-in-time analysis |
| Snyk | Missed | No malware detection |
| Sonatype (Nexus) | Missed | Gradual drift evades signature-based detection |
| Black Duck | Missed | No malware detection |
| Endor Labs | Missed | No malware detection |