@or-sdk/chat@0.3.3
Malicious code in @or-sdk/chat (npm)
Analysis
@or-sdk/chat@0.3.3, a chat-widget SDK, ships a preinstall hook (node setup.mjs) that downloads the Bun JavaScript runtime and then executes a bundled 727KB heavily-obfuscated script (math_init.js) at install time. The script uses a custom string-encoding scheme so its logic is opaque to inspection; the package's own source (dist/) is a plain chat helper with no lifecycle hook, and the changelog documents no such install behaviour. Installing this version runs an obfuscated payload on the machine with network access. The payload's exact actions could not be determined statically due to the obfuscation.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 01:03 PM
- analyzed
- Aug 4, 2026, 02:38 PM
- weekly installs
- 741
Related advisories
- @or-sdk/base@0.44.6
- @or-sdk/sdk-api@0.29.4
- @or-sdk/providers@0.3.8
- @onereach/orest-cli@2.4.3
- @onereach/lambda-invocation@1.2.3
- @onereach/phonenumber-interpreter@0.0.20
- @or-sdk/library-types-v1@9.0.3
- @onereach/si-root@0.9.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.