The package is not classified as malware due to low confidence YARA match, verified provenance, and the project's popularity.
No verification record available.
The package @rolldown/binding-linux-x64-musl is not classified as malware. Although the YARA rule semicolon_relative_path_high matched the .node file, the confidence is low. There's only one YARA rule match, and the matched pattern seems to be part of a debug message or error message, not necessarily indicative of malicious behavior. The project rolldown has a significant number of stars and forks, suggesting it's a legitimate project. Also, SLSA provenance is verified.