HIGH RISK NaN/100

@test20250424/invoice-doc-extractor

Unknown developer

Threat Summary

Risk Level
Critical Issues
High Issues
Total Findings

Key Security Threats

HIGH Malware Signature

YARA rule match: -postinstall_system_command

/tmp/extract-a5904d2dd722642f7d6e6ef481c233af6eab53ab5edddaaf0e8fb35ae1b872b9-237453607/README.md

HIGH Malware Signature

YARA rule match: -UsingCommandLineArguments

/tmp/extract-a5904d2dd722642f7d6e6ef481c233af6eab53ab5edddaaf0e8fb35ae1b872b9-237453607/dist/cli.js

HIGH Malware Signature

YARA rule match: -postinstall_system_command

/tmp/extract-a5904d2dd722642f7d6e6ef481c233af6eab53ab5edddaaf0e8fb35ae1b872b9-237453607/dist/cli.js

HIGH Malware Signature

YARA rule match: -postinstall_registry_modification

/tmp/extract-a5904d2dd722642f7d6e6ef481c233af6eab53ab5edddaaf0e8fb35ae1b872b9-237453607/package.json

All Findings (17)

View all 17 security findings
Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -UsingCommandLineArguments

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -postinstall_registry_modification

filesystem-access

MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/handler.js-7

filesystem-access

MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/handler.js-11

filesystem-access

MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/tools/invoice_doc_extractor.js-6

Indicator of Compromise

XIOC detected Domain: request.id

Indicator of Compromise

XIOC detected Domain: invoice-guidelines.md

Indicator of Compromise

XIOC detected Domain: example.com

Indicator of Compromise

XIOC detected Domain: registry.npmjs.org

Indicator of Compromise

XIOC detected Email: [email protected]

Indicator of Compromise

XIOC detected URL: https://registry.npmjs.org/

filesystem-access

MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/tools/invoice_doc_extractor.js-35

metadata

HASH-6c77c954e81088f2

metadata

HASH-c161b002887507c7

metadata

HASH-f561e51bbccc02d9

Recommended Action

This extension has significant security concerns that warrant careful review. Consider uninstalling or finding a safer alternative. If you must use it, limit the permissions and monitor for suspicious activity.

Analysis performed on 3/10/2026 · Version unknown

Data sourced from automated security scanning. For detailed analysis, view the full security scorecard.