LWA-2026-7980 MAL-2026-11697 ↗ confirmed malware

@or-sdk/hitl@0.41.2

Malicious code in @or-sdk/hitl (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

The package's preinstall hook (setup.mjs) downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun/releases and executes a bundled 727KB obfuscated script (math_init.js) at install time. The obfuscated payload is encoded with a custom alphabet and is not readable; its behaviour is opaque. The package already ships normal compiled builds (dist/cjs, dist/esm, dist/types) that constitute the SDK, so the install-time runtime download and opaque payload execution is separate from the SDK's documented function and is not described in the README or changelog. Installing this package runs the obfuscated payload on the installer's machine.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 11:42 AM
analyzed
Aug 4, 2026, 02:24 PM
weekly installs
1,309

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.