SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple YARA matches for bash persistence and npm preinstall command execution indicate malicious behavior. Package is classified as malware.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. The YARA rule bash_persist_persistent matched in bun_environment.js and setup_bun.js indicate attempts to access bash startup files, potentially for malicious persistence. Additionally, the npm_preinstall_command match in package.json suggests the execution of an external command during the preinstall phase, which is often used for malicious purposes. The combination of these two factors makes a strong case for classifying this package as malware.

victoria-wallet-utils@0.1.2Malicious
Verified
Analysed at: 11/24/25, 4:25 PM
Source: https://registry.npmjs.org/victoria-wallet-utils/-/victoria-wallet-utils-0.1.2.tgz
SHA256: 610983046b5c41617cc3966a86f7dd9d9e78b1055e4a349a52918e9aee168a4a
Confidence: High