LWA-2026-7758 MAL-2026-11835 ↗ confirmed malware

@servicetitan/carto-react-kit@0.8.8

Malicious code in @servicetitan/carto-react-kit (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

The package @servicetitan/carto-react-kit contains a preinstall hook (setup.mjs) that downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun/releases/ and executes a 727KB obfuscated script (math_init.js) with it. The preinstall hook runs automatically during npm install, before any dependencies are installed. The executed script is heavily obfuscated and its behaviour cannot be determined from static analysis alone. The package has no repository URL and no verifiable publisher identity.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 11:22 AM
analyzed
Aug 4, 2026, 11:45 AM
weekly installs
909

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.