SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

The package is flagged as malware due to a suspicious preinstall script and attempts to modify bash startup files, indicating malicious intent.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. The package.json file contains a preinstall script (setup_bun.js) which is flagged as suspicious by an LLM. The npm_preinstall_command YARA rule also matches this. Furthermore, both setup_bun.js and bun_environment.js match the bash_persist_persistent YARA rule, indicating potential attempts to modify bash startup files for persistence. The combination of these factors suggests malicious intent.

@postman/aether-icons@2.23.3Malicious
Verified
Analysed at: 11/24/25, 5:12 AM
Source: https://registry.npmjs.org/@postman/aether-icons/-/aether-icons-2.23.3.tgz
SHA256: ab184940247b7c4c059d1afdd86d1db50161ba6d9402f3b530131af4451d1795
Confidence: High