@workbench-stack/core@3.9.8
Malicious code in @workbench-stack/core (npm)
T1059.007 · JavaScriptT1027 · Obfuscated Files or Information
Analysis
The package's preinstall hook (node setup.mjs) downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun/releases and executes a bundled 727KB heavily-obfuscated script (math_init.js) with it. The script uses a custom string-encoding/array-rotation obfuscation scheme that hides its runtime behavior, so an installer cannot determine what code runs on their machine during install. The obfuscated payload's network and file activity is not visible in the source.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 11:26 AM
- analyzed
- Aug 4, 2026, 02:20 PM
- weekly installs
- 1,090
Related advisories
- @servicetitan/quick-actions@1.15.5
- @servicetitan/html-sketchapp@4.2.11
- @onereach/si-alert@0.4.13
- @onereach/pnpm-audit-junit@1.0.5
- @onereach/si-checkbox@0.6.7
- @onereach/idw-apps@0.1.5
- @onereach/si-list@0.7.6
- @onereach/si-step-chooser@0.4.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.