LWA-2026-10826 confirmed malware

@reducers/projects@99.9.1

Malicious code in @reducers/projects (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

@reducers/projects@99.9.1 is a dependency-confusion stub: a 361-byte package with an empty index.js that declares a dependency "ltidisafe" fetched at install time from a non-registry Google Cloud Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]5[.]8[.]tgz). The package ships no functional code of its own; its sole purpose is to pull and install the remote dependency from the attacker-controlled CDN, delivering the payload to any project that installs it.

analyzed by
Leitwacht
first seen
Aug 8, 2026, 08:09 AM
analyzed
Aug 8, 2026, 08:10 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.