@concerns/i18n@99.9.1
Malicious code in @concerns/i18n (npm)
Analysis
Critical external_url_dep finding: @concerns/i18n@99.9.1 declares dependency on ltidisafe via direct Google Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-2[.]6[.]8[.]tgz) instead of npm registry. Publisher email [account] is throwaway domain. External URL deps bypass npm security scanning and allow silent payload swaps. Package is minimal stub (357 bytes) with empty index.js — classic supply chain attack shape where the real payload comes from the external dependency. Requires human review to determine if ltidisafe URL hosts malicious code.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 03:18 AM
- analyzed
- May 27, 2026, 04:46 AM
Related advisories
- @coterie-baby/common@99.9.1
- unleash-js@99.9.1
- wm-mapper@99.9.1
- dotenv-runtime@1.0.0
- css-jptvix-polyfill@1.0.0
- tailwind-forms-kit@0.5.3
- @pinecone-experience/messages@99.9.1
- hardhat-spack@3.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.