o3forms@99.1.99
Malicious code in o3forms (npm)
Analysis
o3forms@99.1.99 is a supply-chain pre-positioning package. high-major-version alone is minor, but the full profile is damning: 11 bin entries shadowing webpack/vite/eslint/next/jest/prettier/tsc/turbo/nodemon all pointing to the same 350-byte stub; SHA-pinned optionalDependency to github:core-modules-lab/o3forms-utils#76c1c55 (not on npm); config.unsafe-perm:true; publisher using disposable atomicmail[.]io email impersonating OpenMRS Community Contributor. Current payload is a benign stub — classic publish-and-wait: bins are already in place, and a future index.js change or optdep SHA update would silently compromise every developer's build toolchain.
- analyzed by
- Leitwacht
- first seen
- Jun 1, 2026, 02:58 PM
- analyzed
- Jun 1, 2026, 03:05 PM
Related advisories
- @veertly/web-app@100.0.2
- @veygo/component-library@99.9.2
- @visma-net-platform/module-navigator@99.9.1
- @visonum/network-quality-sdk@99.9.9
- @open-banking/cabinet-providers@999.9.5
- @easy-entry/landing-routes@99.9.5
- @easy-entry/outside-registration-fop-navigator@99.9.5
- @easy-entry/routes@99.9.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.