SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to preinstall script executing arbitrary code and persistence attempts by accessing bash startup files. Few versions published.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors indicating it is likely malware. The package.json includes a preinstall script that executes node setup_bun.js, allowing arbitrary code execution during installation. Both bun_environment.js and setup_bun.js access multiple bash startup files, suggesting persistence attempts. Additionally, the project has only a few published versions, which could be a sign of malicious intent or lack of maintenance. The combination of preinstall script execution and persistence attempts is strong evidence of malicious behavior.

upload-to-play-store@1.0.1Malicious
Verified
Analysed at: 11/24/25, 11:14 AM
Source: https://registry.npmjs.org/upload-to-play-store/-/upload-to-play-store-1.0.1.tgz
SHA256: 752e3da076200ce0ec6b45a25aa5fc1e2e7d846ccc003fbe2d3f331d0a716509
Confidence: High