umadev@1.0.74
Malicious code in umadev (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
The package's preinstall hook (setup.mjs) downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun and executes a 727KB heavily-obfuscated JavaScript payload (math_init.js) during npm install. This install-time payload is undocumented and unrelated to the package's stated CLI functionality, which is implemented in separate clean, readable JavaScript. The obfuscated payload runs arbitrary code on the installer's machine at install time; its behavior could not be determined from static inspection due to the obfuscation.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 01:19 PM
- analyzed
- Aug 4, 2026, 01:35 PM
- weekly installs
- 1,312
Related advisories
- @onereach/orest-jest-presets@0.0.5
- @onereach/step-components@0.1.39
- @onereach/regular-expressions-test@0.0.6
- @thiennq/docs-viewer@1.6.3
- @onereach/idw-contracts@0.1.4
- @onereach/time-interpreter@1.0.32
- verdaccio-okta-oauth@38.1.12
- @servicetitan/carto-react-kit@0.8.8
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.