SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple YARA matches and LLM analysis indicate suspicious preinstall script and potential bash persistence attempts, suggesting malicious intent.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package contains multiple suspicious indicators. The YARA rule bash_persist_persistent matched in setup_bun.js and bun_environment.js, suggesting potential attempts to modify bash startup files for persistence. Furthermore, the npm_preinstall_command rule matched in package.json, and the LLM analysis flagged the preinstall script executing node setup_bun.js as suspicious, indicating arbitrary code execution during installation. The combination of these factors suggests malicious intent.

@postman/postman-mcp-cli@1.0.4Malicious
Verified
Analysed at: 11/24/25, 5:11 AM
Source: https://registry.npmjs.org/@postman/postman-mcp-cli/-/postman-mcp-cli-1.0.4.tgz
SHA256: 8e93c91ba43842007e0673ef7b9d8b9d166ec3558d10afad78ddc904783840e9
Confidence: High