LWA-2026-7726 MAL-2026-11940 ↗ confirmed malware

@servicetitan/titan-chatbot-client@2.1.7

Malicious code in @servicetitan/titan-chatbot-client (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or InformationT1071 · Application Layer Protocol

Analysis

The @servicetitan npm organization was compromised. Two packages (@servicetitan/titan-chatbot-client@2.1.7 and @servicetitan/mfe-quick-actions@0.5.52) were published with a preinstall hook (setup.mjs) that downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun/releases and executes a 727KB obfuscated payload (math_init.js) through it. The payload is heavily obfuscated with javascript-obfuscator-style encoding. The legitimate ServiceTitan source code in the packages (chatbot UI components, API service clients) is bundled alongside the malicious preinstall hook and payload.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 11:23 AM
analyzed
Aug 4, 2026, 11:29 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.