LWA-2026-1112 MAL-2026-2680 ↗ confirmed malware

@veygo/component-library@99.9.2

Malicious code in @veygo/component-library (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Dependency-confusion stub targeting the @veygo scope. The 374-byte package contains no real component code — only index.html with 'console.log("ltidisecurethis")'. The main entry point declared in package.json ('index.js') does not exist, and version 99.9.2 is set absurdly high to outrank any legitimate @veygo/component-library. Its sole dependency is an external GCS tarball URL (ltidi[.]storage[.]googleapis[.]com/ltidisafe-1.6.5.tgz). No lifecycle hooks or token-theft markers, but the structure is a dependency-confusion placeholder intended to resolve ahead of a private org package and pull in the external tarball dependency.

analyzed by
Leitwacht
first seen
May 29, 2026, 12:57 AM
analyzed
May 29, 2026, 09:50 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.