LWA-2026-7705 MAL-2026-11779 ↗ confirmed malware

@ornikar/typed-css-modules-loader@0.8.7

Malicious code in @ornikar/typed-css-modules-loader (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

@ornikar/typed-css-modules-loader@0.8.7 is a trojanized clone of the legitimate typed-css-modules-loader. The package ships a preinstall hook (setup.mjs) that downloads the Bun JavaScript runtime binary from github[.]com/oven-sh/bun/releases/download/bun-v1.3.13/ and executes a 727KB obfuscated Bun-compiled payload (math_init.js). The legitimate webpack loader code in index.js is a decoy. The actual payload in math_init.js is compiled with Bun and heavily obfuscated, making its behaviour opaque to static analysis. The package has no repository and no verifiable publisher identity.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 11:16 AM
analyzed
Aug 4, 2026, 11:18 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.