LWA-2026-7754 MAL-2026-11890 ↗ confirmed malware

@servicetitan/marketing-direct-mail-components@20.1.5

Malicious code in @servicetitan/marketing-direct-mail-components (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

The package @servicetitan/marketing-direct-mail-components@20.1.5 is a trojanized version of a legitimate ServiceTitan React component library. The package.json declares a preinstall hook that runs setup.mjs, which downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun/releases and then executes a 727KB heavily-obfuscated payload file (math_init.js) through it. The payload is a Bun-compiled CJS file with javascript-obfuscator encoding, making its behaviour unreadable without deobfuscation. The preinstall hook runs automatically on npm install, giving the obfuscated payload full access to the installer's environment.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 11:24 AM
analyzed
Aug 4, 2026, 11:42 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.