SafeDep
Install GitHub App

Summary

Note: This report is updated by a verification record

Multiple YARA matches indicate suspicious behavior: bash persistence attempts and execution of external commands during preinstall. Likely malware.

Verification Record

Confirmed malicious package as part of coordinated supply chain attack targeting npm ecosystem

Details

Note: This report is updated by a verification record

The package exhibits multiple suspicious behaviors. The bash_persist_persistent YARA rule matched in bun_environment.js and setup_bun.js indicates potential attempts to modify bash startup files for persistence. Additionally, the npm_preinstall_command YARA rule match in package.json suggests the execution of an external command during the preinstall phase, which can be a sign of malicious intent. The combination of these two behaviors raises significant concerns about the package's safety.

valuedex-sdk@3.0.5Malicious
Verified
Analysed at: 11/24/25, 4:52 PM
Source: https://registry.npmjs.org/valuedex-sdk/-/valuedex-sdk-3.0.5.tgz
SHA256: e555942e37251c888293ee242b7710a9afdee04bc205b78e8f2463b1946a05e3
Confidence: High