LWA-2026-10048 MAL-2026-11730 ↗ confirmed malware

@or-sdk/store@2.1.7

Malicious code in @or-sdk/store (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

The package's preinstall hook (node setup.mjs) downloads the Bun runtime from the official oven-sh/bun GitHub release and uses it to execute a bundled 727KB obfuscated script (math_init.js) at install time. The script is obfuscated with a large encoded string array and a custom decoder, concealing its payload. The package also declares a dependency on @or-sdk/base, a known-malicious package, and its SDK classes are built on top of that dependency. Installing this package triggers execution of the obfuscated payload before the library is usable.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 11:59 AM
analyzed
Aug 4, 2026, 05:23 PM
weekly installs
169

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.