@servicetitan/tanstack-query-mobx 6.2.2
Dropper downloads and executes Bun runtime
Obfuscated JavaScript targets AWS and GitHub runner credentialsTemp Bun runtime launches opaque payload
SHA-256868b64be65daff9c3ccb14049b55477cdf8438fd38361b5f3d0d4408ee82a94b
Also flagged by osv (MAL-2026-11930: Malicious code in @servicetitan/tanstack-query-mobx (npm)) +2 more.