@servicetitan/html-sketchapp@4.2.11
Malicious code in @servicetitan/html-sketchapp (npm)
Analysis
A trojanized fork of the html-sketchapp package executes an obfuscated payload at install time. The package adds a preinstall hook (node setup.mjs) that downloads the Bun JavaScript runtime and runs a 727KB heavily-obfuscated bundle (math_init.js) with it. The bundle uses a custom base64 alphabet and string-table obfuscation, hiding all URLs and strings from static inspection. The package's legitimate HTML-to-Sketch conversion code is present in plaintext, but the install hook runs the opaque obfuscated payload regardless. Installing this package executes unknown remote-downloaded code during npm install.
- analyzed by
- Leitwacht
- first seen
- Aug 4, 2026, 11:17 AM
- analyzed
- Aug 4, 2026, 02:13 PM
- weekly installs
- 545
Related advisories
- @servicetitan/anvil-token@0.4.4
- @servicetitan/cp-mfe-dev@1.115.4
- @servicetitan/grid@0.0.66
- @onereach/si-alert@0.4.13
- @onereach/pnpm-audit-junit@1.0.5
- @onereach/si-checkbox@0.6.7
- @onereach/idw-apps@0.1.5
- @onereach/si-list@0.7.6
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.