SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Malicious package due to preinstall script execution and attempts to modify shell startup files for persistence, indicating malicious intent.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. The package.json includes a preinstall script executing node setup_bun.js, which is a known technique for malware to gain access before installation. Both bun_environment.js and setup_bun.js match the bash_persist_persistent YARA rule, indicating potential attempts to modify shell startup files for persistence. The combination of preinstall script execution and shell persistence attempts strongly suggests malicious intent.

victoria-wallet-core@0.1.1Malicious
Verified
Analysed at: 11/24/25, 3:50 PM
Source: https://registry.npmjs.org/victoria-wallet-core/-/victoria-wallet-core-0.1.1.tgz
SHA256: 131f56cbaccac2d8f7f300186e94dc6f65023ed3e477dd6aaddca301397951c4
Confidence: High