SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Low confidence YARA rule bash_persist_persistent matches. Insufficient evidence to classify as malware. Might be related to Bun runtime.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package is not a malware because the YARA rule bash_persist_persistent has low confidence, and it is the only evidence available. Matching this rule alone is not sufficient to classify the package as malware. It could be a false positive. The matched files, bun_environment.js and setup_bun.js, suggest the package might be related to the Bun runtime environment. Modifying shell startup files isn't inherently malicious and could be part of legitimate setup or configuration processes.

v-plausible@1.2.1Malicious
Verified
Analysed at: 11/24/25, 4:48 PM
Source: https://registry.npmjs.org/v-plausible/-/v-plausible-1.2.1.tgz
SHA256: 66d4a7c1eda1ff2692cea50f481d5ae8750cf38014d1989334b8c01197825962
Confidence: High