editable-contracts@0.0.23
Malicious code in editable-contracts (npm)
Analysis
editable-contracts@0.0.23 is a trojanized clone of a legitimate React form library. The preinstall hook (setup.mjs) downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun/releases/download/bun-v1.3.13/ and executes a 727KB heavily obfuscated script (math_init.js) through it. The obfuscated file uses a custom string-decoder with a large constant array — a multi-stage dropper pattern. The legitimate-looking MobX form source code in src/ and dist/ is cover for the install-time payload delivery. The temp directory is cleaned up after execution to hide traces.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 11:29 AM
- analyzed
- Aug 4, 2026, 11:41 AM
Related advisories
- @servicetitan/anvil2-ext-charts@0.2.8
- @servicetitan/titan-chatbot-ui-cypress@9.0.5
- @servicetitan/carto-charts-react@0.0.6
- @servicetitan/titan-chat-ui-anvil2@9.0.5
- @servicetitan/eh-module-communication@0.2.5
- @servicetitan/carto-charts-rn@0.0.6
- @servicetitan/anvil-react@0.11.7
- @servicetitan/marketing-integration-widgets@1.0.44
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.