@mesmerised/socket-detection-eicar
v1.0.0
Published
EICAR-style detection test sample. Source contains many malware-like static patterns but the runtime is inert (proof-of-execution only). For evaluating scanner detection coverage. See README.
Downloads
105
Readme
@mesmerised/socket-detection-eicar
⚠️ DETECTION TEST SAMPLE — NOT REAL MALWARE. EICAR-test-file principle applied to an npm package. The source looks hostile to static scanners, but is provably inert at runtime. Used to characterize the False-Negative behavior of supply-chain scanners.
Runtime behavior
One thing: launches calc.exe (on Windows) as a visible proof-of-execution.
That is the entire functional behavior. No network, no file reads, no env exfiltration, no persistence, no real command execution other than Calculator.
Why it looks hostile (and why that's the point)
The source deliberately exhibits the patterns malware scanners flag:
- a
postinstallinstall script - char-code / hex / base64 string decoders (obfuscation patterns)
- references to
child_process.exec,fs.readFileSync,https.get,net.connect, and indirecteval - a high-entropy byte array (junk — see below)
- recon-looking path strings, a
*.invalid"C2" hostname, a "dropper" command
Every one of these is dead code, gated behind a hard const ARMED = false;.
JavaScript cannot reassign a const, so the hostile routines are unreachable —
the require() calls never execute, the modules are never loaded, the APIs are
never called.
Why the byte array is junk
Earlier drafts used a real msfvenom shellcode stub. Replaced with high-entropy
nonsense bytes (0xde,0xad,0xbe,0xef,...). A static scanner flags a junk byte
array with the same confidence as a real one — so no detection signal is
lost — but no functional offensive code enters the public supply chain.
Interpretation of scanner results
- If a scanner flags this package → it keys on static patterns regardless of runtime behavior (conservative; higher false-positive risk on legitimate code).
- If a scanner clears this package → it does not flag suspicious-but-inert patterns (likely behavior-aware or version/entropy-aware).
Both outcomes are informative for evaluating scanner coverage.
License
MIT
