SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple YARA matches and a suspicious preinstall script executing arbitrary code strongly suggest this package is malware.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. Both bun_environment.js and setup_bun.js trigger the bash_persist_persistent YARA rule, indicating access to multiple bash startup files. Furthermore, the package.json includes a preinstall script that executes node setup_bun.js, allowing arbitrary code execution during installation. This is a strong indicator of malicious intent, especially when combined with the bash persistence behavior. The LLM based file evaluation service also flags the preinstall script as suspicious.

victoria-wallet-validator@0.1.1Malicious
Verified
Analysed at: 11/24/25, 3:49 PM
Source: https://registry.npmjs.org/victoria-wallet-validator/-/victoria-wallet-validator-0.1.1.tgz
SHA256: 30fca9ec8e8de3bc97aab774ebcf42844a7115b25755011d2dc3b49a7aad714c
Confidence: High