LWA-2026-2316 MAL-2026-5450 ↗ confirmed malware

o3forms@99.1.99

Malicious code in o3forms (npm)

Analysis

o3forms@99.1.99 is a supply-chain pre-positioning package. high-major-version alone is minor, but the full profile is damning: 11 bin entries shadowing webpack/vite/eslint/next/jest/prettier/tsc/turbo/nodemon all pointing to the same 350-byte stub; SHA-pinned optionalDependency to github:core-modules-lab/o3forms-utils#76c1c55 (not on npm); config.unsafe-perm:true; publisher using disposable atomicmail[.]io email impersonating OpenMRS Community Contributor. Current payload is a benign stub — classic publish-and-wait: bins are already in place, and a future index.js change or optdep SHA update would silently compromise every developer's build toolchain.

analyzed by
Leitwacht
first seen
Jun 1, 2026, 02:58 PM
analyzed
Jun 1, 2026, 03:05 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.