LWA-2026-0205 MAL-2026-5654 ↗ confirmed malware

@coterie-baby/common@99.9.1

Malicious code in @coterie-baby/common (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

Critical external_url_dep finding is legitimate. Package @coterie-baby/common@99.9.1 declares dependency on hxxps://ltidi[.]storage[.]googleapis[.]com/ltidisafe-2[.]2[.]1[.]tgz - an arbitrary external URL bypassing npm registry security. Publisher email [account] is a throwaway domain. Version 99.9.1 suggests version squatting. Tiny package (358 bytes) with no legitimate purpose other than pulling external code. This is a classic supply chain attack vector - external dependencies allow attackers to serve malicious code outside npm's security controls. Not a false positive.

analyzed by
Leitwacht
first seen
May 27, 2026, 03:34 AM
analyzed
May 27, 2026, 04:05 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.