SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

YARA rule bash_persist_persistent matched, but lacks strong evidence to classify as malware. Likely related to setup/env configuration.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package is not a malware because the YARA rule bash_persist_persistent matched in setup_bun.js and bun_environment.js. This rule indicates access to multiple bash startup files. However, without further evidence of malicious intent, such as suspicious code being written to these files or other unusual behavior, it is difficult to classify this package as malware. It could be related to legitimate setup or environment configuration scripts. The confidence level is also low.

vf-oss-template@1.0.2Malicious
Verified
Analysed at: 11/24/25, 11:30 AM
Source: https://registry.npmjs.org/vf-oss-template/-/vf-oss-template-1.0.2.tgz
SHA256: 60ad372200f45f1bd44f323bc240d0050096aab272e03db777452a6de02061e1
Confidence: High