SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple YARA matches for bash persistence and a suspicious preinstall script that executes arbitrary code indicate malicious behavior.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. Both bun_environment.js and setup_bun.js access multiple bash startup files, indicated by the 'bash_persist_persistent' YARA rule. Additionally, the package.json contains a preinstall script that executes node setup_bun.js, allowing arbitrary code execution during installation. This combination of behaviors, including accessing bash startup files and executing code during installation, strongly suggests malicious intent.

wenk@1.0.10Malicious
Verified
Analysed at: 11/24/25, 10:25 AM
Source: https://registry.npmjs.org/wenk/-/wenk-1.0.10.tgz
SHA256: e7dd9a7986b4334e33357c6efd2132b9c3b3cce222071e01742250208732b629
Confidence: High