LWA-2026-7959 MAL-2026-11645 ↗ confirmed malware

@onereach/si-step-chooser@0.4.6

Malicious code in @onereach/si-step-chooser (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

The package's preinstall hook (setup.mjs) downloads a runtime binary and executes a bundled, heavily-obfuscated payload (math_init.js, ~727KB) at install time. The payload is obfuscated with a javascript-obfuscator-style _0x array and custom decode routine, hiding its behaviour from static inspection. The same bootstrap-and-obfuscated-payload pattern is used across the @onereach scope, whose sibling packages perform DNS-tunnel exfiltration, fetch-and-execute remote code, and evade sandbox analysis at install. Installing this package runs the obfuscated payload on the victim machine during npm install.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 12:37 PM
analyzed
Aug 4, 2026, 02:07 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.