HIGH RISK NaN/100

@tryghost/ghst

Unknown developer

Threat Summary

Risk Level
Critical Issues
High Issues
Total Findings

Key Security Threats

HIGH Malware Signature

YARA rule match: -credential_env_files

/tmp/extract-b4ea3e51dfec7ae9766473546f4b82022847ec8902abd578de3b7e64fdec7a01-3376962494/dist/index.js.map

HIGH Malware Signature

YARA rule match: -postinstall_persistence_mechanism

/tmp/extract-b4ea3e51dfec7ae9766473546f4b82022847ec8902abd578de3b7e64fdec7a01-3376962494/dist/index.js.map

HIGH Malware Signature

YARA rule match: -postinstall_crypto_operations

/tmp/extract-b4ea3e51dfec7ae9766473546f4b82022847ec8902abd578de3b7e64fdec7a01-3376962494/dist/index.js.map

HIGH Malware Signature

YARA rule match: -postinstall_obfuscation

/tmp/extract-b4ea3e51dfec7ae9766473546f4b82022847ec8902abd578de3b7e64fdec7a01-3376962494/dist/index.js.map

HIGH Malware Signature

YARA rule match: -UsingShellInterpreterWhenExecutingOSCommands

/tmp/extract-b4ea3e51dfec7ae9766473546f4b82022847ec8902abd578de3b7e64fdec7a01-3376962494/dist/index.js.map

All Findings (281)

View all 281 security findings
Malware Signature

YARA rule match: -credential_env_files

Malware Signature

YARA rule match: -postinstall_persistence_mechanism

Malware Signature

YARA rule match: -postinstall_crypto_operations

Malware Signature

YARA rule match: -postinstall_obfuscation

Malware Signature

YARA rule match: -UsingShellInterpreterWhenExecutingOSCommands

Malware Signature

YARA rule match: -NoDisableSanitizeHtml

Malware Signature

YARA rule match: -postinstall_file_manipulation

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_file_download

Malware Signature

YARA rule match: -postinstall_system_command

filesystem-access

MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-9634

Malware Signature

YARA rule match: -credential_env_files

Malware Signature

YARA rule match: -postinstall_system_command

Malware Signature

YARA rule match: -postinstall_persistence_mechanism

Malware Signature

YARA rule match: -postinstall_crypto_operations

Malware Signature

YARA rule match: -postinstall_obfuscation

Malware Signature

YARA rule match: -UsingCommandLineArguments

Malware Signature

YARA rule match: -UsingShellInterpreterWhenExecutingOSCommands

Malware Signature

YARA rule match: -NoDisableSanitizeHtml

Malware Signature

YARA rule match: -postinstall_file_manipulation

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_file_download

Malware Signature

YARA rule match: -postinstall_network_communication

credential-access

MCP tool poisoning risk: CREDENTIAL-ACCESS-dist/index.js-8781

filesystem-access

MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-9204

Malware Signature

YARA rule match: -credential_env_files

Malware Signature

YARA rule match: -postinstall_file_manipulation

Malware Signature

YARA rule match: -postinstall_network_communication

Malware Signature

YARA rule match: -postinstall_file_download

Malware Signature

YARA rule match: -postinstall_system_command

filesystem-access

MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-9480

filesystem-access

MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-1127

Malware Signature

YARA rule match: -postinstall_file_manipulation

filesystem-access

MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-1159

filesystem-access

MCP tool poisoning risk: FILESYSTEM-ACCESS-dist/index.js-12244

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Suspicious Network Activity

Network call of type 'fetch' detected.

Indicator of Compromise

XIOC detected Domain: params.next

Suspicious Network Activity

Network call of type 'fetch' detected.

Indicator of Compromise

XIOC detected URL: https://app.example.com

Indicator of Compromise

XIOC detected URL: https://ghost.org/trademark/)

Indicator of Compromise

XIOC detected URL: https://example.com).

Indicator of Compromise

XIOC detected URL: https://.

Indicator of Compromise

XIOC detected URL: https://example.com):

Indicator of Compromise

XIOC detected URL: https://app.example.com.

Indicator of Compromise

XIOC detected URL: https://example.com).',

Indicator of Compromise

XIOC detected Domain: z.email

Indicator of Compromise

XIOC detected Domain: fs.watch

Indicator of Compromise

XIOC detected Domain: github.com

Indicator of Compromise

XIOC detected URL: https://myblog.ghost.io

Indicator of Compromise

XIOC detected URL: https://hooks.example.com/ghost

Indicator of Compromise

XIOC detected URL: https://example.com/.ghost/activitypub/note/1

Indicator of Compromise

XIOC detected URL: https://example.com/users/alice/statuses/1

Indicator of Compromise

XIOC detected Domain: options.events

Indicator of Compromise

XIOC detected Domain: parsed.data.events

Indicator of Compromise

XIOC detected Domain: parsed.data.host

Indicator of Compromise

XIOC detected Domain: event.host

Indicator of Compromise

XIOC detected Domain: event.id

Indicator of Compromise

XIOC detected Domain: program.name

Indicator of Compromise

XIOC detected Domain: index.js.map

Indicator of Compromise

XIOC detected Domain: options.zip

Indicator of Compromise

XIOC detected Domain: parsed.data.zip

Indicator of Compromise

XIOC detected Domain: parsed.data.watch

Indicator of Compromise

XIOC detected Domain: date.now

Indicator of Compromise

XIOC detected Domain: first.id

Indicator of Compromise

XIOC detected Domain: hook.id

Indicator of Compromise

XIOC detected Domain: request.off

Indicator of Compromise

XIOC detected Domain: rangedata.to

Indicator of Compromise

XIOC detected Domain: options.to

Indicator of Compromise

XIOC detected Domain: payload.items.map

Indicator of Compromise

XIOC detected Domain: parsed2.data

Indicator of Compromise

XIOC detected Domain: options.post

Indicator of Compromise

XIOC detected Domain: options.watch

Indicator of Compromise

XIOC detected Domain: fs14.watch

Indicator of Compromise

XIOC detected Domain: z9.email

Indicator of Compromise

XIOC detected Domain: options.at

Indicator of Compromise

XIOC detected Domain: parsed.data.at

Indicator of Compromise

XIOC detected Domain: options.next

Indicator of Compromise

XIOC detected Domain: options.bio

Indicator of Compromise

XIOC detected Domain: parsed.data.next

Indicator of Compromise

XIOC detected Domain: parsedpagination.data.next

Indicator of Compromise

XIOC detected Domain: data.email

Indicator of Compromise

XIOC detected Domain: data.search

Indicator of Compromise

XIOC detected Domain: values.map

Indicator of Compromise

XIOC detected Domain: parsed.data.email

Indicator of Compromise

XIOC detected Domain: parsed.data.search

Indicator of Compromise

XIOC detected Domain: headers.map

Indicator of Compromise

XIOC detected Domain: postdata.author

Indicator of Compromise

XIOC detected Domain: args.post

Indicator of Compromise

XIOC detected Domain: options.host

Indicator of Compromise

XIOC detected Domain: appserver.off

Indicator of Compromise

XIOC detected Domain: process.off

Indicator of Compromise

XIOC detected Domain: parsed.search

Indicator of Compromise

XIOC detected Domain: options.tools

Indicator of Compromise

XIOC detected Domain: z7.email

Indicator of Compromise

XIOC detected Domain: args.at

Indicator of Compromise

XIOC detected Domain: args.email

Indicator of Compromise

XIOC detected Domain: items.map

Indicator of Compromise

XIOC detected Domain: args.page

Indicator of Compromise

XIOC detected Domain: args.top

Indicator of Compromise

XIOC detected Domain: args.target

Indicator of Compromise

XIOC detected Domain: args.bio

Indicator of Compromise

XIOC detected Domain: client.users.me

Indicator of Compromise

XIOC detected Domain: value.next

Indicator of Compromise

XIOC detected Domain: value.name

Indicator of Compromise

XIOC detected Domain: value.bio

Indicator of Compromise

XIOC detected Domain: args.to

Indicator of Compromise

XIOC detected Domain: args.next

Indicator of Compromise

XIOC detected Domain: args.id

Indicator of Compromise

XIOC detected Domain: growth.summary.total

Indicator of Compromise

XIOC detected Domain: client.tags.read

Indicator of Compromise

XIOC detected Domain: tags.map

Indicator of Compromise

XIOC detected Domain: uploadedtheme.name

Indicator of Compromise

XIOC detected Domain: client.tiers.read

Indicator of Compromise

XIOC detected Domain: tiers.map

Indicator of Compromise

XIOC detected Domain: client.users.read

Indicator of Compromise

XIOC detected Domain: row.delta

Indicator of Compromise

XIOC detected Domain: entry.id

Indicator of Compromise

XIOC detected Domain: selectedrows.map

Indicator of Compromise

XIOC detected Domain: selected.map

Indicator of Compromise

XIOC detected Domain: input.id

Indicator of Compromise

XIOC detected Domain: postgrowthsummary.free

Indicator of Compromise

XIOC detected Domain: emailsummary.email

Indicator of Compromise

XIOC detected Domain: row.name

Indicator of Compromise

XIOC detected Domain: statsconfig.id

Indicator of Compromise

XIOC detected Domain: payload.data

Indicator of Compromise

XIOC detected Domain: subscriptionsmeta.totals.map

Indicator of Compromise

XIOC detected Domain: entry.total

Indicator of Compromise

XIOC detected Domain: mrr.map

Indicator of Compromise

XIOC detected Domain: subscriptionshistory.map

Indicator of Compromise

XIOC detected Domain: source.email

Indicator of Compromise

XIOC detected Domain: source.open

Indicator of Compromise

XIOC detected Domain: source.click

Indicator of Compromise

XIOC detected Domain: newsletter.id

Indicator of Compromise

XIOC detected Domain: newsletter.name

Indicator of Compromise

XIOC detected Domain: summary.email

Indicator of Compromise

XIOC detected Domain: existing.date

Indicator of Compromise

XIOC detected Domain: row.free

Indicator of Compromise

XIOC detected Domain: row.total

Indicator of Compromise

XIOC detected Domain: row.email

Indicator of Compromise

XIOC detected Domain: row.open

Indicator of Compromise

XIOC detected Domain: row.click

Indicator of Compromise

XIOC detected Domain: basicstatsrows.map

Indicator of Compromise

XIOC detected Domain: source.free

Indicator of Compromise

XIOC detected Domain: range.to

Indicator of Compromise

XIOC detected Domain: row.date

Indicator of Compromise

XIOC detected Domain: input.to

Indicator of Compromise

XIOC detected Domain: rows.map

Indicator of Compromise

XIOC detected Domain: row.id

Indicator of Compromise

XIOC detected Domain: row.post

Indicator of Compromise

XIOC detected Domain: keys.map

Indicator of Compromise

XIOC detected Domain: settings.social

Indicator of Compromise

XIOC detected Domain: patch.name

Indicator of Compromise

XIOC detected URL: https://.',

Indicator of Compromise

XIOC detected Domain: myblog.ghost.io

Indicator of Compromise

XIOC detected URL: https://app.example.com.',

Indicator of Compromise

XIOC detected Domain: patch.bio

Indicator of Compromise

XIOC detected URL: https://github.com/TryGhost/ghst/issues

Indicator of Compromise

XIOC detected Domain: params.email

Indicator of Compromise

XIOC detected Domain: current.tags.map

Indicator of Compromise

XIOC detected Domain: this.global

Indicator of Compromise

XIOC detected Domain: siteinfo.site

Indicator of Compromise

XIOC detected Domain: settings.map

Indicator of Compromise

XIOC detected Domain: next.next

Indicator of Compromise

XIOC detected Domain: page.next

Indicator of Compromise

XIOC detected Domain: client.newsletters.read

Indicator of Compromise

XIOC detected Domain: newsletters.map

Indicator of Compromise

XIOC detected Domain: client.offers.read

Indicator of Compromise

XIOC detected Domain: offers.map

Indicator of Compromise

XIOC detected Domain: client.pages.read

Indicator of Compromise

XIOC detected Domain: pages.map

Indicator of Compromise

XIOC detected Domain: client.posts.read

Indicator of Compromise

XIOC detected Domain: client.members.read

Indicator of Compromise

XIOC detected Domain: options.email

Indicator of Compromise

XIOC detected Domain: existing.id

Indicator of Compromise

XIOC detected Domain: options.labels.map

Indicator of Compromise

XIOC detected Domain: l.name

Indicator of Compromise

XIOC detected Domain: options.search

Indicator of Compromise

XIOC detected Domain: members.map

Indicator of Compromise

XIOC detected Domain: label.id

Indicator of Compromise

XIOC detected Domain: labels.map

Indicator of Compromise

XIOC detected Domain: options.name

Indicator of Compromise

XIOC detected Domain: data.id

Indicator of Compromise

XIOC detected Domain: data.name

Indicator of Compromise

XIOC detected Domain: parsed.data

Indicator of Compromise

XIOC detected Domain: parsed.data.name

Indicator of Compromise

XIOC detected Domain: parsed.data.id

Indicator of Compromise

XIOC detected Domain: program.commands.map

Indicator of Compromise

XIOC detected Domain: entry.name

Indicator of Compromise

XIOC detected Domain: program.options.map

Indicator of Compromise

XIOC detected Domain: value.map

Indicator of Compromise

XIOC detected Domain: client.labels.read

Indicator of Compromise

XIOC detected Domain: options.id

Indicator of Compromise

XIOC detected Domain: options.params.page

Indicator of Compromise

XIOC detected Domain: current.data

Indicator of Compromise

XIOC detected Domain: result.data

Indicator of Compromise

XIOC detected Domain: chalk2.green

Indicator of Compromise

XIOC detected Domain: options.page

Indicator of Compromise

XIOC detected Domain: value.page

Indicator of Compromise

XIOC detected Domain: parsed.data.page

Indicator of Compromise

XIOC detected Domain: payload.referrers.map

Indicator of Compromise

XIOC detected Domain: payload.growth.map

Indicator of Compromise

XIOC detected Domain: item.date

Indicator of Compromise

XIOC detected Domain: item.free

Indicator of Compromise

XIOC detected Domain: payload.newsletter.open

Indicator of Compromise

XIOC detected Domain: payload.newsletter.click

Indicator of Compromise

XIOC detected Domain: entries.map

Indicator of Compromise

XIOC detected Domain: item.open

Indicator of Compromise

XIOC detected Domain: item.click

Indicator of Compromise

XIOC detected Domain: payload.newsletters.map

Indicator of Compromise

XIOC detected Domain: payload.clicks.map

Indicator of Compromise

XIOC detected Domain: item.post

Indicator of Compromise

XIOC detected Domain: payload.summary.free

Indicator of Compromise

XIOC detected Domain: payload.summary.email

Indicator of Compromise

XIOC detected Domain: theme.name

Indicator of Compromise

XIOC detected Domain: payload.site

Indicator of Compromise

XIOC detected Domain: site.site

Indicator of Compromise

XIOC detected Domain: client.post

Indicator of Compromise

XIOC detected Domain: payload.range.to

Indicator of Compromise

XIOC detected Domain: payload.summary.total

Indicator of Compromise

XIOC detected Domain: payload.posts.map

Indicator of Compromise

XIOC detected Domain: notification.post

Indicator of Compromise

XIOC detected Domain: payload.post

Indicator of Compromise

XIOC detected Domain: ancestor.id

Indicator of Compromise

XIOC detected Domain: child.post

Indicator of Compromise

XIOC detected Domain: child.post.id

Indicator of Compromise

XIOC detected Domain: record.group

Indicator of Compromise

XIOC detected Domain: comments.map

Indicator of Compromise

XIOC detected Domain: report.settings.social

Indicator of Compromise

XIOC detected Domain: account.bio

Indicator of Compromise

XIOC detected Domain: payload.next

Indicator of Compromise

XIOC detected Domain: single.author

Indicator of Compromise

XIOC detected Domain: single.id

Indicator of Compromise

XIOC detected Domain: notifications.map

Indicator of Compromise

XIOC detected Domain: notification.actor

Indicator of Compromise

XIOC detected Domain: record.name

Indicator of Compromise

XIOC detected Domain: record.email

Indicator of Compromise

XIOC detected Domain: posts.map

Indicator of Compromise

XIOC detected Domain: post.author

Indicator of Compromise

XIOC detected Domain: accounts.map

Indicator of Compromise

XIOC detected Domain: account.id

Indicator of Compromise

XIOC detected Domain: account.name

Indicator of Compromise

XIOC detected Domain: member.name

Indicator of Compromise

XIOC detected Domain: member.email

Indicator of Compromise

XIOC detected Domain: record.post

Indicator of Compromise

XIOC detected Domain: record.in

Indicator of Compromise

XIOC detected Domain: record.id

Indicator of Compromise

XIOC detected Domain: member.id

Indicator of Compromise

XIOC detected Domain: post.id

Indicator of Compromise

XIOC detected Domain: chalk.red

Indicator of Compromise

XIOC detected Domain: chalk.blue

Indicator of Compromise

XIOC detected Domain: row.map

Indicator of Compromise

XIOC detected Domain: pagination.page

Indicator of Compromise

XIOC detected Domain: pagination.total

Indicator of Compromise

XIOC detected Domain: fields.map

Indicator of Compromise

XIOC detected Domain: collection.map

Indicator of Compromise

XIOC detected Domain: global.site

Indicator of Compromise

XIOC detected Domain: projectconfig.site

Indicator of Compromise

XIOC detected Domain: process.env.no

Indicator of Compromise

XIOC detected Domain: options.site

Indicator of Compromise

XIOC detected Domain: data.map

Indicator of Compromise

XIOC detected Domain: collectionvalue.map

Indicator of Compromise

XIOC detected Domain: chalk.green

Indicator of Compromise

XIOC detected Domain: ghost.org

Indicator of Compromise

XIOC detected Domain: launch.md

Indicator of Compromise

XIOC detected Domain: contributing.md

Indicator of Compromise

XIOC detected Domain: this.name

Indicator of Compromise

XIOC detected Domain: parsed.error.issues.map

Indicator of Compromise

XIOC detected Domain: parsed.id

Indicator of Compromise

XIOC detected Domain: count.direct

Indicator of Compromise

XIOC detected URL: https://github.com/TryGhost/ghst#readme

Suspicious Network Activity

Network call of type 'fetch' detected.

Indicator of Compromise

XIOC detected URL: https://github.com/TryGhost/ghst.git

Indicator of Compromise

XIOC detected Domain: current.bio

Indicator of Compromise

XIOC detected Domain: current.name

Indicator of Compromise

XIOC detected Domain: args.name

Code Quality Issue

MCP tool poisoning risk: CODE-SMELL-dist/index.js-690

metadata

HASH-3dcd493a23843457

metadata

HASH-56df280a26071c1e

metadata

HASH-ba6dfb1c4ef11b1c

Recommended Action

This extension has significant security concerns that warrant careful review. Consider uninstalling or finding a safer alternative. If you must use it, limit the permissions and monitor for suspicious activity.

Analysis performed on 3/23/2026 · Version unknown

Data sourced from automated security scanning. For detailed analysis, view the full security scorecard.