Hostile 100% javascript Download

sn-listbox 0.3.3

preinstall downloads and executes obfuscated payload

Mini Shai-Hulud setup.mjs preinstall Bun loaderObfuscated JavaScript targets AWS and GitHub runner credentials
SHA-256c29fbbcd2e91aaf823309308992768d83a0b9e96c367234c87e00a63bb6c1f5e

Also flagged by osv (MAL-2026-11987: Malicious code in sn-listbox (npm)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.