LWA-2026-8008 MAL-2026-11728 ↗ confirmed malware

@or-sdk/source-api@1.1.3

Malicious code in @or-sdk/source-api (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

The package's preinstall hook (setup.mjs) downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun and executes a 727KB heavily-obfuscated script (math_init.js) during installation. The obfuscated payload's behavior is opaque and cannot be statically verified; it runs on every install regardless of whether the package is used. No additional network endpoints or credential access were readable in the obfuscated payload.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 11:58 AM
analyzed
Aug 4, 2026, 03:04 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.