Hostile 100% javascript Download

cards 1.2.5

obfuscated dropper downloads and executes payload

Mini Shai-Hulud setup.mjs preinstall Bun loaderObfuscated JavaScript targets AWS and GitHub runner credentials
SHA-25607e362e3a76f6b73c15ee57053cd017ea32bb96975958d4cc44aa259fa802edb

Also flagged by osv (MAL-2026-11680: Malicious code in @or-sdk/cards (npm)) +4 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.