SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Matches for bash persistence and npm preinstall command, but not enough evidence to classify as malware. Lacks strong indicators.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package has two files, bun_environment.js and setup_bun.js, that match the bash_persist_persistent YARA rule, indicating access to multiple bash startup files. This could be used for malicious persistence, but it's also possible that the package is legitimately trying to set up a specific environment for Bun. The package.json file also matches the npm_preinstall_command YARA rule, which indicates that the package runs an external command during the preinstall phase. While this is a potential vector for malicious activity, it's not inherently malicious. Given the low confidence and the lack of stronger indicators, I cannot classify this package as malware.

wallet-evm@0.3.2Malicious
Verified
Analysed at: 11/24/25, 4:25 PM
Source: https://registry.npmjs.org/wallet-evm/-/wallet-evm-0.3.2.tgz
SHA256: b073e23b53e6154adbaf289f56df039f543b912d2df2d7bad171545d967b0576
Confidence: High