SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Package has suspicious preinstall script and files modifying shell startup files, indicating potential malware.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. Both bun_environment.js and setup_bun.js trigger the bash_persist_persistent YARA rule, indicating potential attempts to modify shell startup files for persistence. Additionally, the package.json includes a preinstall script that executes node setup_bun.js, enabling arbitrary code execution during installation, a common malware technique. The combination of these factors suggests malicious intent.

@quick-start-soft/quick-git-clean-markdown@1.4.2511142126Malicious
Verified
Analysed at: 11/24/25, 3:35 AM
Source: https://registry.npmjs.org/@quick-start-soft/quick-git-clean-markdown/-/quick-git-clean-markdown-1.4.2511142126.tgz
SHA256: f195f645c2913d9842ca2a8e3c62985ebbf70bd3291516fba941ab9ccd049129
Confidence: High