SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple pieces of evidence, including arbitrary code execution, silent failures, and bash persistence attempts, indicate that the package is likely malicious.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors that, when combined, strongly suggest malicious intent. Specifically, setup_bun.js downloads and executes a script from an external source without user consent or validation, potentially allowing arbitrary code execution. It also executes bun_environment.js without checks, creating another potential injection point. Furthermore, the error handling in setup_bun.js leads to silent failures, masking potential malicious activity. The YARA rule matches in bun_environment.js and setup_bun.js for bash persistence further contribute to the suspicion. The npm_preinstall_command in package.json adds another layer of concern.

web-scraper-mcp@1.1.4Malicious
Verified
Analysed at: 11/24/25, 9:19 AM
Source: https://registry.npmjs.org/web-scraper-mcp/-/web-scraper-mcp-1.1.4.tgz
SHA256: 01cf3e9375ab0507eb3f1bec572932962947d381902672391635b1b69d73f906
Confidence: High