SafeDep
Install GitHub App
SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple suspicious behaviors: preinstall script, bash persistence, embedded executable with mismatched extension. Likely malware.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors that, when considered together, strongly suggest malicious intent. The package.json includes a preinstall script that executes setup_bun.js, which is flagged as suspicious. Both setup_bun.js and bun_environment.js access multiple bash startup files, indicating potential persistence attempts. Furthermore, the package contains an embedded executable named postman in the bin directory, which has a mismatched file extension. This combination of suspicious preinstall script execution, bash persistence attempts, and an embedded executable with a mismatched extension is highly indicative of malicious activity.

@postman/pm-bin-macos-arm64@1.24.4Malicious
Verified
Analysed at: 11/24/25, 5:12 AM
Source: https://registry.npmjs.org/@postman/pm-bin-macos-arm64/-/pm-bin-macos-arm64-1.24.4.tgz
SHA256: 3e412baba0a923cc8a71d1a165e9ba82f02fe36916982f70049fe004d5910a12
Confidence: High