LWA-2026-7755 MAL-2026-11881 ↗ confirmed malware

@servicetitan/json-render-react@0.4.10

Malicious code in @servicetitan/json-render-react (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

The preinstall hook (setup.mjs) downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun/releases and executes a 727KB Bun-compiled file (math_init.js) during npm install. The Bun-compiled payload is opaque to static analysis. The publisher account ([account]) has a history of publishing malicious packages, indicating the ServiceTitan npm organization was compromised and this version carries an injected preinstall hook that downloads and executes an opaque binary payload at install time.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 11:27 AM
analyzed
Aug 4, 2026, 11:43 AM
weekly installs
319

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.