SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple YARA matches and a suspicious preinstall script executing a file that modifies bash startup files indicate malicious behavior.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. The package.json file contains a preinstall script that executes node setup_bun.js, which is flagged as suspicious. Both setup_bun.js and bun_environment.js match the bash_persist_persistent YARA rule, indicating potential attempts to modify bash startup files for persistence. The npm_preinstall_command YARA rule match in package.json further reinforces the suspicion of malicious intent by running external commands during installation. These multiple indicators strongly suggest malicious behavior.

@postman/postman-mcp-cli@1.0.3Malicious
Verified
Analysed at: 11/24/25, 5:06 AM
Source: https://registry.npmjs.org/@postman/postman-mcp-cli/-/postman-mcp-cli-1.0.3.tgz
SHA256: e307895b8bfc58e30646b006ea3647ee491e06dd721d1ce3a1e38f11f69ac26b
Confidence: High