LWA-2026-7984 MAL-2026-11622 ↗ confirmed malware

@onereach/postcss-scoped-selector@1.2.3

Malicious code in @onereach/postcss-scoped-selector (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

The package's preinstall hook (setup.mjs) downloads the Bun JavaScript runtime from the official oven-sh/bun GitHub releases and executes a bundled 727KB script (math_init.js) with it. math_init.js is obfuscated with a custom string-encoding scheme that hides all of its strings, URLs, and API calls, so its behaviour is not statically readable. A PostCSS selector-scoping plugin has no legitimate need to download a runtime and run an opaque obfuscated payload at install time. No network destination or exfil endpoint could be extracted from the encoded payload.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 01:30 PM
analyzed
Aug 4, 2026, 02:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.