SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple suspicious behaviors: preinstall script execution, bash startup file access, and code obfuscation suggest malicious activity.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. Firstly, the package.json includes a preinstall script that executes node setup_bun.js, enabling arbitrary code execution before installation. This is flagged as suspicious by the LLM. Secondly, both bun_environment.js and setup_bun.js access multiple bash startup files, indicating potential persistence attempts. Finally, victoria-wallet-type.cjs.production.min.js contains XOR-obfuscated terms, suggesting an attempt to hide malicious intent. The combination of preinstall script execution, bash startup file access, and code obfuscation strongly suggests malicious activity.

victoria-wallet-type@0.1.1Malicious
Verified
Analysed at: 11/24/25, 3:50 PM
Source: https://registry.npmjs.org/victoria-wallet-type/-/victoria-wallet-type-0.1.1.tgz
SHA256: d3641c8c9d95260858bc7e001324180b44de2301b5b8bb5c945fadbbea9a0510
Confidence: High