eslint-publish-release@99.9.1
Malicious code in eslint-publish-release (npm)
Analysis
eslint-publish-release@99.9.1 is an empty package (index.js exports an empty object) whose only purpose is to install a dependency named ltidisafe fetched from a non-registry CDN at hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]6[.]4[.]tgz. The package impersonates eslint's release tooling and ships at version 99.9.1, a dependency-confusion shape: installing it pulls attacker-controlled code from the off-registry Google Cloud Storage bucket rather than the npm registry. The bundled code itself is inert; the malicious payload is delivered through the off-registry dependency.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 05:23 AM
- analyzed
- Aug 13, 2026, 05:23 AM
Related advisories
- eslint-generate-prerelease@99.9.1
- @khaznatech/common@99.0.0
- buildifier@1.0.0
- dzvchorehui2@1.0.0
- minimalistic-assert-plus@1.1.7
- @tamago19/tamaaago@2.1.3
- bs58-33@6.0.1
- base65-33x@5.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.