← All analysed packages

npm package

app-soda-layer
version 2.1.6 · detonated 2026-07-27 · isolated sandbox
⚠ Flagged as suspicious
Suspicious command chain
1
node /usr/local/bin/npm install --no-audit --no-fund
2
node test.js
3
sudo chown -R det:det /home/det/.ssh
4
esbuild --version
5
node /tmp/detonate.Dk1VVL/node_modules/.bin/vite build
6
esbuild --service=0.21.5 --ping
What it did
  • Resolved 1 domain(s) during install.
    registry.npmjs.org
  • Read 4 sensitive path(s).
    /etc/passwd/home/det/.npmrc/home/det/.ssh/authorized_keys/tmp/detonate.Dk1VVL/.npmrc

Protet continuously detonates newly-published npm packages in an isolated sandbox and scores what they actually do at install and run time. app-soda-layer 2.1.6 was flagged as suspicious on the strength of the behaviour above — its observed behaviour is consistent with malicious activity. This is automated analysis of public packages and may include false positives; it is not a definitive determination. Browse every package we've flagged.