npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@mesmerised/socket-detection-eicar

v1.0.0

Published

EICAR-style detection test sample. Source contains many malware-like static patterns but the runtime is inert (proof-of-execution only). For evaluating scanner detection coverage. See README.

Downloads

105

Readme

@mesmerised/socket-detection-eicar

⚠️ DETECTION TEST SAMPLE — NOT REAL MALWARE. EICAR-test-file principle applied to an npm package. The source looks hostile to static scanners, but is provably inert at runtime. Used to characterize the False-Negative behavior of supply-chain scanners.

Runtime behavior

One thing: launches calc.exe (on Windows) as a visible proof-of-execution.

That is the entire functional behavior. No network, no file reads, no env exfiltration, no persistence, no real command execution other than Calculator.

Why it looks hostile (and why that's the point)

The source deliberately exhibits the patterns malware scanners flag:

  • a postinstall install script
  • char-code / hex / base64 string decoders (obfuscation patterns)
  • references to child_process.exec, fs.readFileSync, https.get, net.connect, and indirect eval
  • a high-entropy byte array (junk — see below)
  • recon-looking path strings, a *.invalid "C2" hostname, a "dropper" command

Every one of these is dead code, gated behind a hard const ARMED = false;. JavaScript cannot reassign a const, so the hostile routines are unreachable — the require() calls never execute, the modules are never loaded, the APIs are never called.

Why the byte array is junk

Earlier drafts used a real msfvenom shellcode stub. Replaced with high-entropy nonsense bytes (0xde,0xad,0xbe,0xef,...). A static scanner flags a junk byte array with the same confidence as a real one — so no detection signal is lost — but no functional offensive code enters the public supply chain.

Interpretation of scanner results

  • If a scanner flags this package → it keys on static patterns regardless of runtime behavior (conservative; higher false-positive risk on legitimate code).
  • If a scanner clears this package → it does not flag suspicious-but-inert patterns (likely behavior-aware or version/entropy-aware).

Both outcomes are informative for evaluating scanner coverage.

License

MIT