Package contains an embedded executable, but published by a reputable project with verified provenance. Insufficient evidence to flag as malware.
No verification record available.
The package @esbuild/linux-s390x contains an embedded executable file package/bin/esbuild. While this raises a potential security risk, there are legitimate use cases for embedding executables, such as pre-compiled binaries. The package is published by a reputable project evanw/esbuild with a high number of stars and forks. The SLSA provenance is also verified. Without further evidence of malicious behavior, it's not possible to classify this package as malware. The embedded executable is likely a pre-compiled binary for the esbuild tool.