SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple YARA matches and suspicious preinstall script indicate malicious behavior. Shell persistence attempts and arbitrary code execution are concerning.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. The bash_persist_persistent YARA rule matched in setup_bun.js and bun_environment.js indicates potential attempts to modify shell startup files for persistence. Additionally, the npm_preinstall_command YARA rule matched in package.json, coupled with the LLM's assessment of a suspicious preinstall script executing node setup_bun.js, raises concerns about malicious code execution during installation. The preinstall script running setup_bun.js is a strong indicator, especially when combined with the shell persistence attempts.

@postman/wdio-junit-reporter@0.0.4Malicious
Verified
Analysed at: 11/24/25, 5:05 AM
Source: https://registry.npmjs.org/@postman/wdio-junit-reporter/-/wdio-junit-reporter-0.0.4.tgz
SHA256: acae5501667e9f22edb182fb642317d848a1750fc5075de4606786ac5b1c11e4
Confidence: High