@servicetitan/carto-react-kit@0.8.8
Malicious code in @servicetitan/carto-react-kit (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer
Analysis
The package @servicetitan/carto-react-kit contains a preinstall hook (setup.mjs) that downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun/releases/ and executes a 727KB obfuscated script (math_init.js) with it. The preinstall hook runs automatically during npm install, before any dependencies are installed. The executed script is heavily obfuscated and its behaviour cannot be determined from static analysis alone. The package has no repository URL and no verifiable publisher identity.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 11:22 AM
- analyzed
- Aug 4, 2026, 11:45 AM
- weekly installs
- 909
Related advisories
- @servicetitan/anvil-token@0.4.4
- @servicetitan/cp-mfe-dev@1.115.4
- @servicetitan/grid@0.0.66
- verdaccio-tarball-local-storage@38.1.12
- @servicetitan/json-render-react@0.4.10
- @servicetitan/marketing-direct-mail-components@20.1.5
- folder-lint@1.0.17
- editable-contracts@0.0.23
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.