LWA-2026-8004 MAL-2026-11887 ↗ confirmed malware

@servicetitan/line-item-editor@1.5.4

Malicious code in @servicetitan/line-item-editor (npm)

T1059.007 · JavaScriptT1105 · Ingress Tool Transfer

Analysis

The package's preinstall hook (node setup.mjs) downloads the Bun runtime from the official oven-sh GitHub release and then executes a bundled 727KB heavily-obfuscated script (math_init.js) at install time. The install-time payload is obfuscated with a dictionary-array/string-encoding scheme, so its behavior is not readable. A React UI component library executing a large obfuscated script downloaded-and-run at install is anomalous and unverifiable; the payload's network and file activity could not be confirmed benign.

analyzed by
Leitwacht
first seen
Aug 4, 2026, 02:49 PM
analyzed
Aug 4, 2026, 02:58 PM
weekly installs
2,227

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.