@veygo/component-library@99.9.2
Malicious code in @veygo/component-library (npm)
Analysis
Dependency-confusion stub targeting the @veygo scope. The 374-byte package contains no real component code — only index.html with 'console.log("ltidisecurethis")'. The main entry point declared in package.json ('index.js') does not exist, and version 99.9.2 is set absurdly high to outrank any legitimate @veygo/component-library. Its sole dependency is an external GCS tarball URL (ltidi[.]storage[.]googleapis[.]com/ltidisafe-1.6.5.tgz). No lifecycle hooks or token-theft markers, but the structure is a dependency-confusion placeholder intended to resolve ahead of a private org package and pull in the external tarball dependency.
- analyzed by
- Leitwacht
- first seen
- May 29, 2026, 12:57 AM
- analyzed
- May 29, 2026, 09:50 PM
Related advisories
- @visma-net-platform/module-navigator@99.9.1
- @visonum/network-quality-sdk@99.9.9
- @open-banking/cabinet-providers@999.9.5
- @easy-entry/landing-routes@99.9.5
- @easy-entry/outside-registration-fop-navigator@99.9.5
- @easy-entry/routes@99.9.5
- @shell-cabinet/routes@99.9.5
- @shell-landing/routes@99.9.5
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.