@onescience/onecode — install-time dropper
The npm postinstall hook downloads and executes a binary from a hardcoded raw IP with TLS validation turned off.
@onescience/onecode version 1.14.50-202609231732 ships a postinstall lifecycle hook that runs platform-bootstrap.mjs. On install the script fetches a payload from a hardcoded raw IP address and executes it, with TLS certificate validation explicitly disabled — a textbook install-time dropper.
This build is one in a long sequence of malicious releases for the package, already catalogued upstream as MAL-2026-10717. codelake confirms the same behaviour in this specific version.
218.90.133.98 (raw IPv4, no domain)rejectUnauthorized: false)postinstall → platform-bootstrap.mjs (runs on every install)Public immediately — a confirmed malicious actor, no identity to protect. Catalogued upstream as MAL-2026-10717; this advisory records codelake's confirmation of the behaviour in build 1.14.50-202609231732.