LWA-2026-7982 MAL-2026-11832 ↗ confirmed malware

@servicetitan/carto-charts-core@0.0.6

Malicious code in @servicetitan/carto-charts-core (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool TransferT1027 · Obfuscated Files or Information

Analysis

The package's preinstall hook (setup.mjs) downloads the Bun JavaScript runtime from github[.]com/oven-sh/bun and executes a 727KB heavily-obfuscated script, math_init.js, during npm install. The script is obfuscated with a javascript-obfuscator string-array/decoder pattern that hides its behavior from inspection. The package's declared purpose is an ECharts chart-theming library, and its shipped dist/ code is a normal chart library — the obfuscated install-time payload is unrelated to that purpose and runs automatically on every install. The payload's network and data-access behavior is concealed by the obfuscation.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 11:48 AM
analyzed
Aug 4, 2026, 02:22 PM
weekly installs
169

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.