Analyze your own packages withvet GitHub

@esbuild/darwin-arm64@0.25.11

Suspicious
Analyzed at:10/15/2025, 2:12:10 AM
Source:https://registry.npmjs.org/@esbuild/darwin-arm64/-/darwin-arm64-0.25.11.tgz
SHA256:42ea27b04af4aaf177f5a6fa5cb6dda85d21ecd2fa45adb865cc3430eb985e2e
Confidence:Medium
Summary

This analysis was performed using vet and SafeDep Cloud Malicious Package Analysis. Integrate with GitHub using vet-action GitHub Action.

Embedded executable, extension mismatch, and suspicious YARA rule match indicate potential malicious activity. High risk.

Details

The package contains an embedded executable (package/bin/esbuild) which is unusual for a typical npm package. The file extension mismatch and the YARA rule match 'high_entropy_trailer' further raise suspicion, suggesting potential malicious activity or code injection. The combination of these factors indicates a high risk.