LWA-2026-0200 MAL-2026-6606 ↗ confirmed malware

@concerns/i18n@99.9.1

Malicious code in @concerns/i18n (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Critical external_url_dep finding: @concerns/i18n@99.9.1 declares dependency on ltidisafe via direct Google Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-2[.]6[.]8[.]tgz) instead of npm registry. Publisher email [account] is throwaway domain. External URL deps bypass npm security scanning and allow silent payload swaps. Package is minimal stub (357 bytes) with empty index.js — classic supply chain attack shape where the real payload comes from the external dependency. Requires human review to determine if ltidisafe URL hosts malicious code.

analyzed by
Leitwacht
first seen
May 27, 2026, 03:18 AM
analyzed
May 27, 2026, 04:46 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.