{
  "schema_version": "1.6.0",
  "id": "MAL-2026-10717",
  "modified": "2026-10-01T12:00:00Z",
  "published": "2026-10-01T12:00:00Z",
  "summary": "@onescience/onecode — install-time dropper",
  "details": "The npm postinstall hook downloads and executes a binary from a hardcoded raw IP with TLS validation turned off.",
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "@onescience/onecode"
      },
      "versions": [
        "1.14.50-202609231732"
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://research.codelake.dev/advisories/clr-2026-3062-onescience-onecode"
    },
    {
      "type": "WEB",
      "url": "https://osv.dev/vulnerability/MAL-2026-10717"
    },
    {
      "type": "ADVISORY",
      "url": "https://osv.dev/vulnerability/MAL-2026-10717"
    }
  ],
  "credits": [
    {
      "name": "Sascha Klein, codelake Research",
      "type": "FINDER",
      "contact": [
        "https://research.codelake.dev"
      ]
    }
  ],
  "database_specific": {
    "caseId": "CLR-2026-3062",
    "kind": "malware",
    "class": "Malware — install-time dropper",
    "severity": "Critical",
    "status": "Published",
    "iocs": {
      "ips": [
        "218.90.133.98"
      ],
      "hashes": [],
      "indicators": [
        "Download host: 218.90.133.98 (raw IPv4, no domain)",
        "TLS certificate validation disabled (rejectUnauthorized: false)",
        "Trigger: npm postinstall → platform-bootstrap.mjs (runs on every install)",
        "Behaviour: download + execute remote binary at install time"
      ]
    }
  }
}