SafeDep
Install GitHub App
Start for Free
SafeDep
Install GitHub App
Start for Free

Summary

Note: This report is updated by a verification record

Multiple suspicious behaviors: bash persistence, preinstall command, embedded executable, and extension mismatch indicate malware.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package contains multiple suspicious behaviors. The YARA rule bash_persist_persistent matched in setup_bun.js and bun_environment.js indicates potential attempts to modify bash startup files for persistence. The npm_preinstall_command match in package.json suggests the execution of external commands during installation, which can be a vector for malicious code injection. Furthermore, the presence of an embedded executable package/bin/postman and an extension mismatch raise concerns about the package's integrity and potential for malicious intent. The combination of these factors strongly suggests that the package is a malware.

@postman/pm-bin-macos-arm64@1.24.5Malicious
Verified
Analysed at: 11/24/25, 5:15 AM
Source: https://registry.npmjs.org/@postman/pm-bin-macos-arm64/-/pm-bin-macos-arm64-1.24.5.tgz
SHA256: f7b61e63c8045520465d519203b2380f2f0d354854d473d8cae72d70866c3762
Confidence: High