Analyze your own packages withvet GitHub

@img/sharp-libvips-linuxmusl-x64@1.2.3

Safe
Analyzed at:9/23/2025, 5:58:14 PM
Source:https://registry.npmjs.org/@img/sharp-libvips-linuxmusl-x64/-/sharp-libvips-linuxmusl-x64-1.2.3.tgz
SHA256:f6dd073b436f2a3d57ca12f5de0fbff2b52b50f50c944dc274ffd6c9ca3000b0
Confidence:Medium
Summary

This analysis was performed using vet and SafeDep Cloud Malicious Package Analysis. Integrate with GitHub using vet-action GitHub Action.

Package is likely not malware. Contains a pre-compiled binary, which is a valid use case. SLSA provenance is verified.

Details

The package @img/sharp-libvips-linuxmusl-x64 version 1.2.3 is likely not malware. While it contains an embedded executable (libvips-cpp.so.8.17.2) and exhibits an extension mismatch, the project sharp-libvips has a reasonable number of stars (200) and forks (113) on GitHub, suggesting it's a legitimate project. The SLSA provenance is also verified. The embedded executable is likely a pre-compiled binary, which is a valid use case. The extension mismatch is unusual but not necessarily indicative of malicious intent.