@coterie-baby/common@99.9.1
Malicious code in @coterie-baby/common (npm)
Analysis
Critical external_url_dep finding is legitimate. Package @coterie-baby/common@99.9.1 declares dependency on hxxps://ltidi[.]storage[.]googleapis[.]com/ltidisafe-2[.]2[.]1[.]tgz - an arbitrary external URL bypassing npm registry security. Publisher email [account] is a throwaway domain. Version 99.9.1 suggests version squatting. Tiny package (358 bytes) with no legitimate purpose other than pulling external code. This is a classic supply chain attack vector - external dependencies allow attackers to serve malicious code outside npm's security controls. Not a false positive.
- analyzed by
- Leitwacht
- first seen
- May 27, 2026, 03:34 AM
- analyzed
- May 27, 2026, 04:05 AM
Related advisories
- unleash-js@99.9.1
- wm-mapper@99.9.1
- @ethers-js/contracts@6.9.0
- @solana-js/web3@1.91.3
- @reducers/projects@99.9.1
- specials-resources-server@35.8.1
- @kolbo/mcp@1.57.1
- sme-rko-finance-front-operations-penalty@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.