LWA-2026-10826 confirmed malware
@reducers/projects@99.9.1
Malicious code in @reducers/projects (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
@reducers/projects@99.9.1 is a dependency-confusion stub: a 361-byte package with an empty index.js that declares a dependency "ltidisafe" fetched at install time from a non-registry Google Cloud Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]5[.]8[.]tgz). The package ships no functional code of its own; its sole purpose is to pull and install the remote dependency from the attacker-controlled CDN, delivering the payload to any project that installs it.
- analyzed by
- Leitwacht
- first seen
- Aug 8, 2026, 08:09 AM
- analyzed
- Aug 8, 2026, 08:10 AM
Related advisories
- specials-resources-server@35.8.1
- @kolbo/mcp@1.57.1
- sme-rko-finance-front-operations-penalty@35.8.1
- sme-rko-finance-front-operations-overnight@35.8.1
- sme-rko-finance-front-operations-pegasus@35.8.1
- sme-rko-finance-front-operations-fee@35.8.1
- sme-rko-finance-front-operations-domain@35.8.1
- sme-rko-finance-front-operations-feed-models@35.8.1
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.