Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

@servicetitan/widget-platformnpm

@servicetitan/widget-platform is a confirmed malicious npm package (MAL-2026-11950) that steals credentials and exfiltrates sensitive data (malicious versions 5.6.1, 5.6.2, 5.6.3…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in @servicetitan/widget-platform (npm)

MAL-2026-11950
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
npm uninstall @servicetitan/widget-platform

What this malware does

npm/@servicetitan/widget-platform is affected by the large-scale, self-propagating npm supply-chain worm of 2026-08-04 (the "Shai-Hulud: Here We Go Again" wave) — the same campaign that began with the compromise of the keyv and cacheable maintainer account. The listed version(s) were trojanized and republished by the worm after it reached an npm publish token belonging to a maintainer in this namespace; the payload enumerates every package a stolen token controls and republishes each with the same hook, so many packages under this scope were poisoned in the same short window. Every poisoned release adds a preinstall hook ("preinstall": "node setup.mjs") that runs on a bare npm install, before any project code. setup.mjs downloads a standalone Bun runtime and runs a byte-identical, heavily obfuscated ~728 KB second-stage credential stealer (shipped as Math_Symbol.js / math_init.js). It harvests GitHub, npm, AWS, GCP, Azure, HashiCorp Vault and Kubernetes credentials plus generic secrets and private keys (TruffleHog-style sweep), reads CI/CD secrets and identifies build runners, then republishes further packages the stolen token can reach. Rather than a fixed command-and-control host, it exfiltrates stolen findings to attacker-created GitHub repositories (descriptions reading "Shai-Hulud: Here We Go Again") and over DNS. Treat any environment that installed an affected version (with install scripts enabled) as compromised: rotate and revoke all reachable credentials (npm and GitHub tokens, cloud keys, Vault/Kubernetes secrets, and CI org/repo secrets). Part of the August 2026 npm worm that poisoned 400+ packages across many organizations.

package.json declares "preinstall": "node setup.mjs". setup.mjs downloads the Bun runtime from github.com/oven-sh/bun releases (v1.3.13) into a temp directory, unzips it, chmods the binary executable, and invokes it with a sibling file math_init.js via execFileSync. math_init.js is a ~727 KB single-line obfuscator.io-style payload (indexed constants array, WV8StW string-array rotator, _0xNNNN renamed identifiers) that is not referenced by the library's dist/index.js entrypoint and has no relationship to the package's stated purpose (a React widget platform with peer deps on react, @servicetitan/react-ioc, @servicetitan/web-components). The obfuscated payload is executed under an alternate runtime specifically so that Node-based tooling does not observe its behavior, and this fires unconditionally during npm install. This matches the alternate-runtime-dropper pattern: the runtime is fetched from its official domain, but it is then used to execute a bundled, opaque payload whose contents cannot be inspected and which serves no purpose relating to the advertised library. The scope @servicetitan/* and version 5.6.1 are consistent with the impersonation pattern of the mini-shai-hulud family targeting vendor scopes; regardless of attribution, the mechanism itself is install-time execution of an obfuscated payload on every installer's machine.

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Malicious versions

7 flagged
5.6.15.6.25.6.35.6.45.6.55.6.65.6.7

Indicators of compromise (SHA-256)

b722288ae23b62e27cf7247abac7150afd37ae6784378b5a14043279cdb12dbb
0dc014c4babcb5fe57b07e99cf2d4e2993fc498b4b6ea6960ba66997b581ad6f
2e3ce1f0afc2781eb76d49674ed6b199a4d28a4d16729bccf0108541c2b2e03b
a976d62dcd47b531475fe55d5bc4a693db97dd3b52eccc2fce7ba5fb56b89ad3
c41e9ae13ffa28a38d5a0c5e0d7ac7fa3a5e93b857a06a1ffc4a3ba77959fc96
ca73c04822f24aa50dc429b964a80cfb9e313cec58ed6f395983f957a1f1966e
cd3d5584db89888429fba687f2528ae08231533b8f052d179772e9a721f3c2b1
293bbdbe97284d37fe11647c4c55fd426a92c23a9a97ac81da4deadb79a0045b

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for @servicetitan/widget-platform (7 malicious versions). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging @servicetitan/widget-platform across your stack and pipelines.

  2. If you installed it — respond

    @servicetitan/widget-platform is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If @servicetitan/widget-platform was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks @servicetitan/widget-platform before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. @servicetitan/widget-platform on npm has been identified as a malicious package (versions 5.6.1, 5.6.2, 5.6.3, 5.6.4, 5.6.5, 5.6.6, 5.6.7 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

GHSA-v4w7-xg9f-9jwqIN-MAL-2026-012051IN-MAL-2026-012222IN-MAL-2026-012160IN-MAL-2026-012270IN-MAL-2026-012376IN-MAL-2026-012640IN-MAL-2026-012736

References

Credits

  • Aikido Security · finder
  • Amazon Inspector · finder
  • SafeDep · finder
  • Socket Threat Research Team · finder

Detect & block this

O3 blocks @servicetitan/widget-platform-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

Explore

@servicetitan/widget-platform (npm) malicious package — MAL-2026-11950 | O3 Security