SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple suspicious indicators: embedded executable with fake headers, preinstall script, and bash startup file access. Likely malicious.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package contains multiple suspicious indicators. It contains an embedded executable (package/bin/postman). The executable package/bin/postman also matched the YARA rule fake_section_headers_conflicting_entry_point_address, indicating potential obfuscation or malicious intent. Additionally, the package.json contains a preinstall script, which is a common technique used by malware to execute malicious code upon installation. The files setup_bun.js and bun_environment.js access multiple bash startup files, indicating potential persistence mechanisms. These multiple pieces of evidence suggest that the package is likely malicious.

@postman/pm-bin-linux-x64@1.24.5Malicious
Verified
Analysed at: 11/24/25, 5:15 AM
Source: https://registry.npmjs.org/@postman/pm-bin-linux-x64/-/pm-bin-linux-x64-1.24.5.tgz
SHA256: c57275b3a5e0894a6eb085c4141790a9dc9f0f703a46e213deba8677e395a96f
Confidence: High