LWA-2026-7751 MAL-2026-11829 ↗ confirmed malware

@servicetitan/anvil2-mcp@0.0.13

Malicious code in @servicetitan/anvil2-mcp (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScript

Analysis

The package @servicetitan/anvil2-mcp@0.0.13 contains a preinstall hook (setup.mjs) that downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun and executes a 727KB heavily obfuscated JavaScript bundle (math_init.js). The preinstall hook runs automatically on npm install, downloading a binary runtime and executing an obfuscated payload whose behaviour cannot be verified from static analysis alone. The package has no repository URL.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 11:25 AM
analyzed
Aug 4, 2026, 11:38 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.