LWA-2026-7939 MAL-2026-11593 ↗ confirmed malware

@onereach/channel-transformers@0.0.7

Malicious code in @onereach/channel-transformers (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

The package's preinstall hook (node setup.mjs) downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun and executes a bundled 727KB heavily-obfuscated payload (math_init.js) at install time. The package is a channel-data-transform library with no legitimate need to download a runtime and run an opaque obfuscated blob during installation. The obfuscated payload's behaviour cannot be statically determined and is executed on every install.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 01:19 PM
analyzed
Aug 4, 2026, 01:48 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.