bun-dev

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Anomaly
AnomalyLOW
references/ref-bun-release-notes-bun-v1.3.10.md

This document is a release/install README for Bun and is not itself malicious code. However, it explicitly recommends high-risk installation patterns (curl | bash and Invoke-Expression PowerShell) and several remote package/image installation vectors (npm, brew, scoop, docker). Those instructions constitute supply-chain risk: if the remote installer, package registry, or image is compromised, an attacker could execute arbitrary code on users' machines. Recommendation: avoid piping remote scripts directly to shell; inspect downloaded install scripts, prefer package manager checksums/signatures or verified binaries, and use least-privilege installation methods. No direct signs of malware in the supplied text.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 19, 2026, 04:57 AM
Package URL
pkg:socket/skills-sh/BjornMelin%2Fdev-skills%2Fbun-dev%2F@65c21acd945f486299b6b96aacb01ffde2743df3
Security Audit — socket — bun-dev