SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple YARA matches for bash persistence and a preinstall script executing a JS file indicate malicious behavior. Likely malware.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. Both bun_environment.js and setup_bun.js trigger the bash_persist_persistent YARA rule, indicating potential attempts to modify shell startup files for persistence. More concerning is the package.json file's preinstall script executing node setup_bun.js. This allows arbitrary code execution before installation, a common malware technique. The combination of these factors strongly suggests malicious intent.

@quick-start-soft/quick-markdown-image@1.4.2511142126Malicious
Verified
Analysed at: 11/24/25, 3:40 AM
Source: https://registry.npmjs.org/@quick-start-soft/quick-markdown-image/-/quick-markdown-image-1.4.2511142126.tgz
SHA256: 340fdfe80dffbb48dedb4ff2a33f8b3627c75654e21e085504684ff7c5058b37
Confidence: High