Analyze your own packages withvet GitHub

@rolldown/binding-linux-arm64-musl@1.0.0-beta.45

Safe
Analyzed at:10/27/2025, 5:59:36 AM
Source:https://registry.npmjs.org/@rolldown/binding-linux-arm64-musl/-/binding-linux-arm64-musl-1.0.0-beta.45.tgz
SHA256:3da0dc82fb4adfbc289c0613e4b5b7af80de9e19c60ef9ab8dd7f1be4d73c776
Confidence:Medium
Summary

This analysis was performed using vet and SafeDep Cloud Malicious Package Analysis. Integrate with GitHub using vet-action GitHub Action.

Low confidence YARA matches on .node file are not sufficient to classify the package as malware. Requires stronger evidence.

Details

The YARA rules libc_fake_number_val and semicolon_relative_path_high matched the .node file, but the confidence is low. These matches alone are not strong enough evidence to classify the package as malware. A non-standard libc reference could indicate an attempt to evade security measures, but without further evidence, it's not definitive. Similarly, relative paths are common.