SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

YARA rule bash_persist_persistent matched with LOW confidence. Insufficient evidence to classify as malware.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package is not a malware because the YARA rule bash_persist_persistent matched in setup_bun.js and bun_environment.js files with LOW confidence. Although the rule indicates access to multiple bash startup files, this could be part of the intended functionality of the package. Without stronger evidence or a clear malicious intent, it's not possible to classify the package as malware. There are multiple negative matching patterns included in the rule, which could indicate a high false positive rate.

vf-oss-template@1.0.4Malicious
Verified
Analysed at: 11/24/25, 1:11 PM
Source: https://registry.npmjs.org/vf-oss-template/-/vf-oss-template-1.0.4.tgz
SHA256: f39885c8f00194fdd8418bdabbba723ed8ee40b5da3299306951cf859e3f28eb
Confidence: High