SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple YARA matches indicate suspicious behavior: bash persistence attempts and preinstall script execution. Likely malicious.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits suspicious behavior based on multiple YARA rule matches. The bash_persist_persistent rule matched in bun_environment.js and setup_bun.js, indicating potential attempts to modify shell startup files for persistence. Additionally, the npm_preinstall_command rule matched in package.json, suggesting the execution of external commands during the preinstall phase. This combination of behaviors raises concerns about the package's safety and suggests it may be malicious.

valid-south-african-id@1.0.3Malicious
Verified
Analysed at: 11/24/25, 10:15 AM
Source: https://registry.npmjs.org/valid-south-african-id/-/valid-south-african-id-1.0.3.tgz
SHA256: 5178498db386f736bf5a88db83fb21f47b47432daa35c2f25a9a61eee19d230b
Confidence: High