OpenSSF/OSV advisory MAL-2026-11950 confirms this npm version as malicious. npm/@servicetitan/widget-platform is affected by the large-scale, self-propagating npm supply-chain worm of 2026-08-04 (the "Shai-Hulud: Here We Go Again" wave) — the same campaign that began with the compromise of the keyv and cacheable maintainer account...
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
math_init.jsView on unpkg · L1Manifest entrypoint contains risky behavior absent from dist/build output.
setup.mjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
setup.mjsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
math_init.jsView on unpkg · L1Manifest entrypoint contains risky behavior absent from dist/build output.
setup.mjsView on unpkg · L1This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
setup.mjsView on unpkg