Low version count, but decent GitHub stats. No strong evidence of malicious intent. Assuming not malware without further evidence.
No verification record available.
The package has only one version published, which raises a flag for potential risk due to immaturity or lack of maintenance. However, the project has a decent number of stars and forks on GitHub, suggesting some level of community trust and activity. There is no strong evidence to classify it as malware based solely on the number of versions and project stats. Without any SLSA provenances or YARA rule matches, it's safer to assume it's not malicious.