@servicetitan/json-render-react@0.4.10
Malicious code in @servicetitan/json-render-react (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
The preinstall hook (setup.mjs) downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun/releases and executes a 727KB Bun-compiled file (math_init.js) during npm install. The Bun-compiled payload is opaque to static analysis. The publisher account ([account]) has a history of publishing malicious packages, indicating the ServiceTitan npm organization was compromised and this version carries an injected preinstall hook that downloads and executes an opaque binary payload at install time.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 11:27 AM
- analyzed
- Aug 4, 2026, 11:43 AM
- weekly installs
- 319
Related advisories
- @servicetitan/anvil-token@0.4.4
- @servicetitan/cp-mfe-dev@1.115.4
- @servicetitan/grid@0.0.66
- @servicetitan/marketing-direct-mail-components@20.1.5
- folder-lint@1.0.17
- editable-contracts@0.0.23
- @servicetitan/anvil2-ext-charts@0.2.8
- @servicetitan/carto-rn-kit@0.0.14
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.