LWA-2026-11137 confirmed malware

eslint-generate-prerelease@99.9.1

Malicious code in eslint-generate-prerelease (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

eslint-generate-prerelease@99.9.1 is a dependency-confusion package: a near-empty stub (index.js exports an empty object) whose only real content is a dependency `ltidisafe` pinned to a non-registry URL, `hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]6[.]2[.]tgz`, a Google Cloud Storage bucket. Installing the package pulls and installs that remote tarball from the CDN instead of the npm registry, so the actual payload is attacker-controlled and served from outside the registry. The package ships at version 99.9.1 on a name that mimics eslint tooling.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 05:19 AM
analyzed
Aug 13, 2026, 05:19 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.