@or-sdk/tables@0.28.7
Malicious code in @or-sdk/tables (npm)
Analysis
The package's preinstall hook (node setup.mjs) downloads the Bun runtime from github[.]com/oven-sh/bun and uses it to execute a bundled 727KB obfuscated script (math_init.js) at install time. The script is obfuscated with a custom string-array decoder and contains eval/Function/child_process usage. The package also depends on @or-sdk/base, a sibling package flagged as malicious. The obfuscated payload's network targets are not statically recoverable; the observable is a multi-stage install-time dropper that fetches a runtime and runs a large obfuscated payload during installation.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 11:56 AM
- analyzed
- Aug 4, 2026, 05:37 PM
- weekly installs
- 143
Related advisories
- @or-sdk/base@0.44.6
- @or-sdk/sdk-api@0.29.4
- @or-sdk/providers@0.3.8
- @or-sdk/store@2.1.7
- @or-sdk/bots@1.7.3
- @or-sdk/card-templates@2.2.7
- @or-sdk/keys@1.2.8
- @or-sdk/graph@1.10.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.