LWA-2026-0073 MAL-2026-4826 ↗ confirmed malware

wm-mapper@99.9.1

Malicious code in wm-mapper (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Critical external_url_dep finding: package wm-mapper@99.9.1 declares dependency on ltidisafe via direct Google Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-2[.]7[.]5[.]tgz) instead of npm registry. This is a known supply chain attack vector - bypasses npm security checks, URL could serve malicious code, domain could be compromised. Publisher email [account] appears throwaway. Package is minimal (350 bytes). External URL dependencies are inherently risky and warrant human review.

analyzed by
Leitwacht
first seen
May 26, 2026, 06:31 PM
analyzed
May 26, 2026, 06:58 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.