@or-sdk/api-tokens-lambda@1.4.4
Malicious code in @or-sdk/api-tokens-lambda (npm)
T1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
The package ships a preinstall hook (`node setup.mjs`) that downloads the Bun runtime (v1.3.13) from github[.]com/oven-sh/bun and then executes a 727KB heavily-obfuscated JavaScript file `math_init.js` at install time. The payload is obfuscated with javascript-obfuscator (hex-encoded string array with a custom decode routine) and its behavior is opaque; the library's own AWS Lambda client code does not require Bun or this script. Installing the package runs this obfuscated payload on the installer's machine.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 01:20 PM
- analyzed
- Aug 4, 2026, 03:20 PM
- weekly installs
- 560
Related advisories
- @or-sdk/base@0.44.6
- @or-sdk/sdk-api@0.29.4
- @or-sdk/providers@0.3.8
- @servicetitan/grid@0.0.66
- @onereach/v-event-calendar@0.1.24
- @onereach/or-content-builder-renderer@0.0.4
- @or-sdk/qna@3.4.4
- @onereach/orest-input-cli@1.18.3
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.