LWA-2026-7977 MAL-2026-11989 ↗ confirmed malware

umadev@1.0.74

Malicious code in umadev (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

The package's preinstall hook (setup.mjs) downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun and executes a 727KB heavily-obfuscated JavaScript payload (math_init.js) during npm install. This install-time payload is undocumented and unrelated to the package's stated CLI functionality, which is implemented in separate clean, readable JavaScript. The obfuscated payload runs arbitrary code on the installer's machine at install time; its behavior could not be determined from static inspection due to the obfuscation.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 01:19 PM
analyzed
Aug 4, 2026, 01:35 PM
weekly installs
1,312

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.