LWA-2026-8016 MAL-2026-11677 ↗ confirmed malware

@or-sdk/bot-templates@2.2.7

Malicious code in @or-sdk/bot-templates (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1027 · Obfuscated Files or Information

Analysis

The package runs a preinstall hook (node setup.mjs) that downloads the Bun runtime and executes a bundled 727KB obfuscated JavaScript payload (math_init.js) at install time. The payload is protected by a custom string-array obfuscation scheme, making its behaviour opaque to inspection. The package also declares dependencies on @or-sdk/base and @or-sdk/data-hub-svc, which are part of the same malicious dependency chain. Installing this package executes the obfuscated payload on the victim's machine during npm install.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 11:59 AM
analyzed
Aug 4, 2026, 03:09 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.