LWA-2026-7702 MAL-2026-11739 ↗ confirmed malware

@ornikar/apollo-link-timeout@1.4.3

Malicious code in @ornikar/apollo-link-timeout (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

The package @ornikar/apollo-link-timeout@1.4.3 is a trojanized version of the legitimate apollo-link-timeout library. The package.json declares a preinstall hook (node setup.mjs) that downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun/releases/download/bun-v1.3.13/ (platform-specific zip) and executes a heavily obfuscated 727KB bundle (math_init.js) through the downloaded runtime. The legitimate library has no preinstall hook and no Bun dependency. The obfuscated payload's behaviour cannot be determined from static analysis alone, but the pattern of downloading a runtime and executing obfuscated code at install time is a supply-chain attack vector.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 10:39 AM
analyzed
Aug 4, 2026, 11:11 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.