LWA-2026-7946 MAL-2026-11646 ↗ confirmed malware

@onereach/si-switch@0.4.7

Malicious code in @onereach/si-switch (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

The package's preinstall hook (setup.mjs) downloads a Bun runtime and executes a heavily-obfuscated 727KB JavaScript bundle (math_init.js) at install time on every machine that installs it. The obfuscated payload is unrelated to the package's declared function as a Vue switch UI component. The same preinstall hook and obfuscated-payload pattern is shared with the sibling package @onereach/webform@0.3.15, whose bundled code performs remote code fetch-and-execute, reads host identity (hostname/user/platform) alongside DNS resolution, and depends on the known-malicious @onereach/channel-transformer. Installing this package executes the obfuscated payload during npm install.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 01:31 PM
analyzed
Aug 4, 2026, 01:55 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.