SafeDep
Install GitHub App

Summary

Insufficient evidence to classify as malware. Code execution via Function constructor is common, and YARA rule match is likely a false positive.

Verification Record

No verification record available.

Details

The package is not a malware because, while there are two pieces of evidence, neither is strong enough to classify the package as malicious on its own. Evidence 0 suggests arbitrary code execution via the Function constructor, but this is a common pattern in many legitimate JavaScript applications, especially those dealing with dynamic code generation or SSR. Evidence 1 shows a YARA rule match for python_exec_complex in a JavaScript file, which is often a false positive. Since there is no other strong evidence, the package is not classified as malware.

vitest@4.1.0Clean
Unverified
Analysed at: 4/13/26, 1:42 AM
Source: https://registry.npmjs.org/vitest/-/vitest-4.1.0.tgz
SHA256: cd6a680ef953796a775fa1412498b7e890ecda5f0ace1f9011574f6875d341d8
Confidence: Medium