LWA-2026-7944 MAL-2026-11631 ↗ confirmed malware

@onereach/si-checkbox-group@0.3.7

Malicious code in @onereach/si-checkbox-group (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

A dormant Vue component package was republished with a preinstall hook (node setup.mjs) that downloads the Bun JavaScript runtime and then executes a 727KB heavily-obfuscated payload (math_init.js) bundled in the package. The payload uses a bespoke obfuscation scheme (a base64-alphabet decoder over a large string table) and its behaviour cannot be statically verified; the package's own lib/ bundles are legitimate Vue/vuelidate/lodash code, so the obfuscated payload is the only executed code of concern. Installing this package runs the obfuscated payload at install time.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 12:39 PM
analyzed
Aug 4, 2026, 01:50 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.