@onereach/postcss-scoped-selector@1.2.3
Malicious code in @onereach/postcss-scoped-selector (npm)
Analysis
The package's preinstall hook (setup.mjs) downloads the Bun JavaScript runtime from the official oven-sh/bun GitHub releases and executes a bundled 727KB script (math_init.js) with it. math_init.js is obfuscated with a custom string-encoding scheme that hides all of its strings, URLs, and API calls, so its behaviour is not statically readable. A PostCSS selector-scoping plugin has no legitimate need to download a runtime and run an opaque obfuscated payload at install time. No network destination or exfil endpoint could be extracted from the encoded payload.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 01:30 PM
- analyzed
- Aug 4, 2026, 02:20 PM
Related advisories
- @onereach/ui-components@27.0.4
- @onereach/ui-components-vue2@27.0.4
- @onereach/expression-components@9.1.3
- @servicetitan/quick-actions@1.15.5
- @onereach/regular-expressions@0.5.25
- @onereach/messengers-infobip-sdk@0.1.3
- @servicetitan/html-sketchapp@4.2.11
- @onereach/orest-vue-demi-vue2@0.0.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.