@servicetitan/design-system 14.5.4
Obfuscated payload, preinstall Bun dropper
Obfuscated JavaScript targets AWS and GitHub runner credentialspreinstall setup.mjs bootstraps Bun runtime
SHA-256843230606ef8a19b2c9b9f5d0f9f601ffe0bf36f14e2101daeab352f98126df2
Also flagged by osv (MAL-2026-11852: Malicious code in @servicetitan/design-system (npm)) +2 more.