LWA-2026-8025 MAL-2026-11670 ↗ confirmed malware

@or-sdk/api-tokens-lambda@1.4.4

Malicious code in @or-sdk/api-tokens-lambda (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

The package ships a preinstall hook (`node setup.mjs`) that downloads the Bun runtime (v1.3.13) from github[.]com/oven-sh/bun and then executes a 727KB heavily-obfuscated JavaScript file `math_init.js` at install time. The payload is obfuscated with javascript-obfuscator (hex-encoded string array with a custom decode routine) and its behavior is opaque; the library's own AWS Lambda client code does not require Bun or this script. Installing the package runs this obfuscated payload on the installer's machine.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 01:20 PM
analyzed
Aug 4, 2026, 03:20 PM
weekly installs
560

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.