Note: This report is updated by a verification record
Package has suspicious preinstall script and files modifying shell startup files, indicating potential malware.
Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem
Note: This report is updated by a verification record
The package exhibits multiple suspicious behaviors. Both bun_environment.js and setup_bun.js trigger the bash_persist_persistent YARA rule, indicating potential attempts to modify shell startup files for persistence. Additionally, the package.json includes a preinstall script that executes node setup_bun.js, enabling arbitrary code execution during installation, a common malware technique. The combination of these factors suggests malicious intent.