Note: This report is updated by a verification record
Package uses preinstall script to execute a JS file that modifies bash startup files, indicating potential malicious persistence behavior.
Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem
Note: This report is updated by a verification record
The package exhibits multiple suspicious behaviors. The package.json contains a preinstall script that executes node setup_bun.js. Both setup_bun.js and bun_environment.js match the bash_persist_persistent YARA rule, indicating potential modification of bash startup files for persistence. The LLM-based file evaluation service also flags the preinstall script as suspicious. The combination of these factors suggests malicious intent.