Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Stage 1 – Loader (setup.mjs) : Télécharge un runtime Bun standalone ... Exécute le second stage via Bun ... La compromission repose sur un hook preinstall ( setup.mjs ) ajouté au package.json .
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Version 7.0.4 introduced three files and a single added line in package.json that turned every npm install into remote code execution.
Because the attacker pushed malicious files straight to each repository’s main branch and then immediately cut a new release, the poisoned versions were published to npm carrying valid provenance signatures generated by GitHub Actions
Le compte maintainer Jaredwray a été compromis et utilisé pour publier des versions malveillantes... La compromission repose sur un hook preinstall (setup.mjs) ajouté au package.json.
If the malware executed on a developer machine (via npm install), it drops several persistence mechanisms: .vscode/tasks.json with a folderOpen task that re-executes the malware on every VS Code workspace open.
Every affected package received two new files, setup.mjs and Math_Symbol.js, along with a “preinstall” hook silently added to package.json that automatically executes setup.mjs during npm install.
The implementation also follows HTTP redirects without validating the destination and uses PowerShell with -ExecutionPolicy Bypass on Windows, increasing the risk for affected developer and CI/CD environments.
Stage 1 – Loader (setup.mjs) : Télécharge un runtime Bun standalone... Exécute le second stage via Bun
La compromission repose sur un hook preinstall (setup.mjs) ajouté au package.json... Stage 2 – Payload (Math_Symbol.js, ~728 KB)
в package.json появлялся preinstall-скрипт node setup.mjs. В результате вредонос запускался автоматически при выполнении npm install, еще до завершения установки пакета.
In the SAP wave, the compromised packages added a preinstall hook that ran setup.mjs... This wave uses a slightly different route... That Git dependency contains a prepare script: "scripts" : { "prepare" : "bun run tanstack_runner.js && exit 1" } This is the trick. npm runs lifecycle scripts for Git dependencies during installation.
Once triggered, setup.mjs functions as a heavily obfuscated dropper
The payload creates a new branch named dependabout/github_actions/format/setup-formatter ... The commit impersonates Dependabot ... The commit author and message are carefully chosen: claude <claude@users.noreply.github.com>
в package.json появлялся preinstall-скрипт node setup.mjs. В результате вредонос запускался автоматически при выполнении npm install, еще до завершения установки пакета.
In the SAP wave, the compromised packages added a preinstall hook that ran setup.mjs... This wave uses a slightly different route... That Git dependency contains a prepare script: "scripts" : { "prepare" : "bun run tanstack_runner.js && exit 1" } This is the trick. npm runs lifecycle scripts for Git dependencies during installation.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
First-stage loader delivered through a malicious npm preinstall hook. It downloads a platform-specific standalone Bun runtime, executes the second-stage payload, avoids some Node-focused monitoring, and removes temporary download artifacts afterward.
Initial loader dropped by the malicious npm preinstall hook. It downloads a standalone Bun runtime and launches the second-stage payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.