SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Package uses preinstall script to execute a JS file that modifies bash startup files, indicating potential malicious persistence behavior.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. The package.json contains a preinstall script that executes node setup_bun.js. Both setup_bun.js and bun_environment.js match the bash_persist_persistent YARA rule, indicating potential modification of bash startup files for persistence. The LLM-based file evaluation service also flags the preinstall script as suspicious. The combination of these factors suggests malicious intent.

@postman/aether-icons@2.23.4Malicious
Verified
Analysed at: 11/24/25, 5:15 AM
Source: https://registry.npmjs.org/@postman/aether-icons/-/aether-icons-2.23.4.tgz
SHA256: 35a8804dedcde4f82be7768e5b7de67df2e246ab2e1d03824f016acbd354b674
Confidence: High