@onereach/si-switch@0.4.7
Malicious code in @onereach/si-switch (npm)
Analysis
The package's preinstall hook (setup.mjs) downloads a Bun runtime and executes a heavily-obfuscated 727KB JavaScript bundle (math_init.js) at install time on every machine that installs it. The obfuscated payload is unrelated to the package's declared function as a Vue switch UI component. The same preinstall hook and obfuscated-payload pattern is shared with the sibling package @onereach/webform@0.3.15, whose bundled code performs remote code fetch-and-execute, reads host identity (hostname/user/platform) alongside DNS resolution, and depends on the known-malicious @onereach/channel-transformer. Installing this package executes the obfuscated payload during npm install.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 01:31 PM
- analyzed
- Aug 4, 2026, 01:55 PM
Related advisories
- @onereach/ui-components@27.0.4
- @onereach/ui-components-vue2@27.0.4
- @onereach/expression-components@9.1.3
- @onereach/si-a-button@0.0.5
- @onereach/si-checkbox-group@0.3.7
- @onereach/channel-transformer@0.0.68
- @onereach/channel-transformers@0.0.7
- @onereach/content-builder-template-compiler@0.0.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.