SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple suspicious behaviors: preinstall script executing arbitrary code and bash persistence attempts indicate malicious intent.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. The package.json includes a preinstall script executing node setup_bun.js, enabling arbitrary code execution before installation. This is further supported by YARA rule matches for npm_preinstall_command in package.json. Additionally, the YARA rule bash_persist_persistent matched in both setup_bun.js and bun_environment.js, indicating potential attempts to modify bash startup files for persistence. These multiple pieces of evidence strongly suggest malicious intent.

@postman/wdio-allure-reporter@0.0.8Malicious
Verified
Analysed at: 11/24/25, 5:11 AM
Source: https://registry.npmjs.org/@postman/wdio-allure-reporter/-/wdio-allure-reporter-0.0.8.tgz
SHA256: d4f0cb0afbc7a927b67fa967ba74b3526986efbf4c3e220b2a26b8cf284dd582
Confidence: High