LWA-2026-11139 confirmed malware
check-audit@99.9.1
Malicious code in check-audit (npm)
T1195.002 · Compromise Software Supply ChainT1059 · Command and Scripting Interpreter
Analysis
check-audit@99.9.1 is an empty stub package (its only code is an empty module export) that declares a dependency on a tarball fetched from a non-registry CDN at hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]6[.]5[.]tgz. The package is published at version 99.9.1 on a name resembling an internal tool, and its sole function is to pull and install that external tarball as a dependency, making it a dependency-confusion supply-chain vector. The malicious payload is delivered via the external ltidisafe tarball rather than the stub's own source.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 05:24 AM
- analyzed
- Aug 13, 2026, 05:24 AM
Related advisories
- mutex-forge@2.0.1
- kit-map-vim@1.0.0
- dakumangalsingh@1.0.0
- kit-vim-map@1.0.0
- dayjs-advanced@1.2.0
- hex-encode-utils@1.0.5
- godot-kit@1.0.1786316795
- simple-date-formatter-new-10@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.