SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to preinstall script execution and attempts to modify shell startup files for persistence.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors strongly suggesting it is malware. The package.json includes a preinstall script that executes node setup_bun.js, enabling arbitrary code execution during installation. Both bun_environment.js and setup_bun.js access multiple bash startup files, indicating potential persistence mechanisms. The combination of preinstall script execution and attempts to modify shell startup files provides strong evidence of malicious intent.

url-encode-decode@1.0.1Malicious
Verified
Analysed at: 11/24/25, 10:05 AM
Source: https://registry.npmjs.org/url-encode-decode/-/url-encode-decode-1.0.1.tgz
SHA256: 2c0f172acf4b8a74bf5669860ac897e1f71255623df2ed1be62a9c9824cc6f98
Confidence: High