Hostile 100% javascript Download

@servicetitan/anvil-icon 0.5.6

Obfuscated payload, preinstall downloads/executes Bun

Obfuscated JavaScript targets AWS and GitHub runner credentialspreinstall setup.mjs bootstraps Bun runtime

Also flagged by osv (MAL-2026-11817: Malicious code in @servicetitan/anvil-icon (npm)) +2 more.

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.