Note: This report is updated by a verification record
Suspicious preinstall script executing arbitrary code and accessing bash startup files indicates malicious activity. Package is classified as malware.
Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem
Note: This report is updated by a verification record
The package exhibits multiple suspicious behaviors. The package.json contains a preinstall script executing node setup_bun.js, allowing arbitrary code execution during installation. Both bun_environment.js and setup_bun.js trigger the bash_persist_persistent YARA rule, indicating access to multiple bash startup files, a common persistence technique. The combination of these factors strongly suggests malicious intent.