LWA-2026-7966 MAL-2026-11878 ↗ confirmed malware

@servicetitan/html-sketchapp@4.2.11

Malicious code in @servicetitan/html-sketchapp (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

A trojanized fork of the html-sketchapp package executes an obfuscated payload at install time. The package adds a preinstall hook (node setup.mjs) that downloads the Bun JavaScript runtime and runs a 727KB heavily-obfuscated bundle (math_init.js) with it. The bundle uses a custom base64 alphabet and string-table obfuscation, hiding all URLs and strings from static inspection. The package's legitimate HTML-to-Sketch conversion code is present in plaintext, but the install hook runs the opaque obfuscated payload regardless. Installing this package executes unknown remote-downloaded code during npm install.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 11:17 AM
analyzed
Aug 4, 2026, 02:13 PM
weekly installs
545

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.