LWA-2026-11139 confirmed malware

check-audit@99.9.1

Malicious code in check-audit (npm)

T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting Interpreter

Analysis

check-audit@99.9.1 is an empty stub package (its only code is an empty module export) that declares a dependency on a tarball fetched from a non-registry CDN at hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]6[.]5[.]tgz. The package is published at version 99.9.1 on a name resembling an internal tool, and its sole function is to pull and install that external tarball as a dependency, making it a dependency-confusion supply-chain vector. The malicious payload is delivered via the external ltidisafe tarball rather than the stub's own source.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 05:24 AM
analyzed
Aug 13, 2026, 05:24 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.