Embedded executable is not inherently malicious; high GitHub stars and forks reduce suspicion; needs further analysis.
No verification record available.
The evidence is inconclusive to label the package as malware. While Evidence 0 indicates the presence of an embedded executable, this is not inherently malicious. Many legitimate packages, especially those involving compilation or build tools (like esbuild), include executables. The fact that it's an ELF file is expected given the package name suggests a Linux/FreeBSD binary. Evidence 1, a low-confidence extension mismatch, is not sufficient to indicate malicious intent. The project's high star count (38498) and fork count (1176) on GitHub suggest a well-established and reputable project, further reducing the likelihood of malicious activity. Without further analysis (e.g., static or dynamic analysis of the executable itself, checking for suspicious network activity, or code review), we cannot definitively classify this package as malware.