Embedded executable and extension mismatch are suspicious, but the package has verified provenance and is from a known project using pre-compiled binaries.
No verification record available.
The package contains an embedded executable (libvips-cpp.so.8.17.3), which raises a security concern. The file extension .3 does not match the detected elf extension. However, the package is published by the lovell/sharp-libvips project with 201 stars and 115 forks, and has verified provenance. The sharp-libvips library is known to use pre-compiled binaries, which explains the embedded executable. Given this context, the evidence is not strong enough to classify the package as malware.