wm-mapper@99.9.1
Malicious code in wm-mapper (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
Critical external_url_dep finding: package wm-mapper@99.9.1 declares dependency on ltidisafe via direct Google Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-2[.]7[.]5[.]tgz) instead of npm registry. This is a known supply chain attack vector - bypasses npm security checks, URL could serve malicious code, domain could be compromised. Publisher email [account] appears throwaway. Package is minimal (350 bytes). External URL dependencies are inherently risky and warrant human review.
- analyzed by
- Leitwacht
- first seen
- May 26, 2026, 06:31 PM
- analyzed
- May 26, 2026, 06:58 PM
Related advisories
- @ethers-js/contracts@6.9.0
- @solana-js/web3@1.91.3
- @reducers/projects@99.9.1
- specials-resources-server@35.8.1
- @kolbo/mcp@1.57.1
- sme-rko-finance-front-operations-penalty@35.8.1
- sme-rko-finance-front-operations-overnight@35.8.1
- sme-rko-finance-front-operations-pegasus@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.