SafeDep
Install GitHub App
Start for Free
SafeDep
Install GitHub App
Start for Free

Summary

Note: This report is updated by a verification record

Multiple suspicious behaviors, including preinstall script, bash startup access, embedded executable with fake headers, indicate potential malware.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors that, when combined, suggest malicious intent. The package.json file contains a preinstall script executing node setup_bun.js, which is flagged as suspicious. Both setup_bun.js and bun_environment.js access multiple bash startup files, potentially for persistence. Furthermore, the package includes an embedded executable package/bin/postman that has fake section headers, a common technique used to evade detection. While each of these findings alone might not be conclusive, their combination raises significant concerns about the package's safety.

@postman/pm-bin-linux-x64@1.24.4Malicious
Verified
Analysed at: 11/24/25, 5:12 AM
Source: https://registry.npmjs.org/@postman/pm-bin-linux-x64/-/pm-bin-linux-x64-1.24.4.tgz
SHA256: 3414dd97256f4d0772e762686e82b6c68ca7a481561e33a2678ce106e82a7b1c
Confidence: High