SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple YARA rule matches and suspicious preinstall script execution strongly suggest malicious intent, classifying the package as malware.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors that, when combined, strongly suggest malicious intent. Specifically, the package.json file contains a preinstall script that executes setup_bun.js. Both bun_environment.js and setup_bun.js trigger the bash_persist_persistent YARA rule, indicating attempts to modify shell startup files for persistence. The npm_preinstall_command YARA rule is also triggered. The preinstall script execution is further flagged as suspicious by the LLM based file evaluation service. These multiple indicators provide a strong case for classifying this package as malware.

wenk@1.0.9Malicious
Verified
Analysed at: 11/24/25, 10:08 AM
Source: https://registry.npmjs.org/wenk/-/wenk-1.0.9.tgz
SHA256: 2168aa687e024dcb05fc1e7c73c744458eef6938ae79bc4b4ffa6961d2c45e29
Confidence: High