LWA-2026-7997 MAL-2026-11709 ↗ confirmed malware

@or-sdk/library-types-v1@9.0.3

Malicious code in @or-sdk/library-types-v1 (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

The package's preinstall hook (node setup.mjs) downloads the Bun JavaScript runtime from GitHub releases and then executes a bundled 727KB obfuscated script (math_init.js) at install time. The package is a types library with no legitimate need to download a runtime or run an opaque, string-array-obfuscated payload during installation; the payload's actual behaviour is not statically analyzable. Installing this package triggers remote binary download plus execution of an obfuscated script on the installer's machine.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 01:01 PM
analyzed
Aug 4, 2026, 02:35 PM
weekly installs
330

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.