@or-sdk/hitl@0.41.2
Malicious code in @or-sdk/hitl (npm)
Analysis
The package's preinstall hook (setup.mjs) downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun/releases and executes a bundled 727KB obfuscated script (math_init.js) at install time. The obfuscated payload is encoded with a custom alphabet and is not readable; its behaviour is opaque. The package already ships normal compiled builds (dist/cjs, dist/esm, dist/types) that constitute the SDK, so the install-time runtime download and opaque payload execution is separate from the SDK's documented function and is not described in the README or changelog. Installing this package runs the obfuscated payload on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 11:42 AM
- analyzed
- Aug 4, 2026, 02:24 PM
- weekly installs
- 1,309
Related advisories
- @or-sdk/base@0.44.6
- @or-sdk/sdk-api@0.29.4
- @or-sdk/providers@0.3.8
- @servicetitan/carto-charts-core@0.0.6
- @onereach/step-run-snowflake-query@0.1.3
- @onereach/postcss-scoped-selector@1.2.3
- @servicetitan/quick-actions@1.15.5
- @onereach/regular-expressions@0.5.25
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.