LWA-2026-7722 MAL-2026-11935 ↗ confirmed malware

@servicetitan/titan-chat-ui@7.1.7

Malicious code in @servicetitan/titan-chat-ui (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

The npm account for @servicetitan/titan-chat-ui was compromised. Version 7.1.7 contains a preinstall hook (setup.mjs) that downloads the Bun JavaScript runtime from the official Bun GitHub releases and executes a heavily obfuscated 727KB payload file (math_init.js). The package also depends on @servicetitan/titan-chat-ui-common, which is a known-malicious package from the same compromised account. The obfuscated payload is the attack vector; the Bun bootstrap is the delivery mechanism. No network exfiltration endpoints were observed in the bootstrap code, but the obfuscated payload's behaviour cannot be determined from static analysis alone.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 11:23 AM
analyzed
Aug 4, 2026, 11:28 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.