SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple YARA matches for bash persistence and a suspicious preinstall script executing arbitrary code indicate malicious behavior.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package contains multiple indicators of suspicious behavior. Both setup_bun.js and bun_environment.js access multiple bash startup files, as detected by the bash_persist_persistent YARA rule. Additionally, the package.json file contains a preinstall script that executes node setup_bun.js, enabling arbitrary code execution during installation. This is further flagged as suspicious by an LLM-based file evaluation service. The combination of these factors strongly suggests malicious intent.

@postman/wdio-junit-reporter@0.0.5Malicious
Verified
Analysed at: 11/24/25, 5:11 AM
Source: https://registry.npmjs.org/@postman/wdio-junit-reporter/-/wdio-junit-reporter-0.0.5.tgz
SHA256: 54e7669c59ab40add0e47a98e639e60a6cfe1933bac5d61b23f76b1d380da596
Confidence: High