⛔ Critical — Malware Detected 2026-10-01 · UTC
Confirmed malicious. codelake independently detected this at 2026-10-01 · UTC — OSV MAL-2026-10717 first published 2026-08-07; codelake confirms the same dropper in build 1.14.50-202609231732. Also documented publicly: MAL-2026-10717 (OSV, 2026-08-07).
Advisory · CLR-2026-3062

@onescience/onecode — install-time dropper

The npm postinstall hook downloads and executes a binary from a hardcoded raw IP with TLS validation turned off.

CriticalnpmMAL-2026-10717
Summary

@onescience/onecode version 1.14.50-202609231732 ships a postinstall lifecycle hook that runs platform-bootstrap.mjs. On install the script fetches a payload from a hardcoded raw IP address and executes it, with TLS certificate validation explicitly disabled — a textbook install-time dropper.

This build is one in a long sequence of malicious releases for the package, already catalogued upstream as MAL-2026-10717. codelake confirms the same behaviour in this specific version.

Dropper indicators — platform-bootstrap.mjs
platform-bootstrap.mjs postinstall
16// download host — a raw IPv4, no domain, no TLS trust anchor
17host = '218.90.133.98'
101rejectUnauthorized: false // TLS certificate validation disabled
Indicators of compromise
🌐Download host: 218.90.133.98 (raw IPv4, no domain)
🔓TLS certificate validation disabled (rejectUnauthorized: false)
⚙️Trigger: npm postinstall → platform-bootstrap.mjs (runs on every install)
💥Behaviour: download + execute remote binary at install time
Remediation
#ActionPriority
1 Remove @onescience/onecode and audit any host that ran npm install with it present. Now
2 Treat the install host as compromised: rotate credentials/tokens reachable from it and inspect for the fetched binary and outbound connections to 218.90.133.98. Now
3 Block the raw IP egress and add postinstall-script review to CI (e.g. --ignore-scripts by default). Soon

Public immediately — a confirmed malicious actor, no identity to protect. Catalogued upstream as MAL-2026-10717; this advisory records codelake's confirmation of the behaviour in build 1.14.50-202609231732.