LWA-2026-11138 confirmed malware

eslint-publish-release@99.9.1

Malicious code in eslint-publish-release (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

eslint-publish-release@99.9.1 is an empty package (index.js exports an empty object) whose only purpose is to install a dependency named ltidisafe fetched from a non-registry CDN at hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]6[.]4[.]tgz. The package impersonates eslint's release tooling and ships at version 99.9.1, a dependency-confusion shape: installing it pulls attacker-controlled code from the off-registry Google Cloud Storage bucket rather than the npm registry. The bundled code itself is inert; the malicious payload is delivered through the off-registry dependency.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 05:23 AM
analyzed
Aug 13, 2026, 05:23 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.