SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple suspicious behaviors: preinstall script, bash startup access, and XOR obfuscation strongly suggest malicious intent. Malware detected.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. The package.json contains a preinstall script executing node setup_bun.js, allowing arbitrary code execution during installation. Both bun_environment.js and setup_bun.js access multiple bash startup files, indicating persistence attempts. Additionally, victoria-wallet-type.cjs.production.min.js contains XOR-obfuscated terms, suggesting obfuscation of potentially malicious code. These multiple strong indicators suggest malicious intent.

victoria-wallet-type@0.1.2Malicious
Verified
Analysed at: 11/24/25, 4:25 PM
Source: https://registry.npmjs.org/victoria-wallet-type/-/victoria-wallet-type-0.1.2.tgz
SHA256: cf391f49640d9de3439f443fd3195744a3603287a1b7e5181647d70c4051941d
Confidence: High