LWA-2026-11140 confirmed malware

resolve-audit@99.9.1

Malicious code in resolve-audit (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

resolve-audit@99.9.1 is an empty package (index.js exports an empty object, no install hooks) that declares a single dependency, ltidisafe, fetched from a non-registry CDN URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]6[.]6[.]tgz) rather than the npm registry. Installing the package pulls and executes this off-registry tarball from an attacker-controlled Google Cloud Storage bucket, delivering the payload outside the registry's scanning and integrity controls. The package ships no functional code of its own; its entire purpose is to install the remote dependency.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 05:25 AM
analyzed
Aug 13, 2026, 05:25 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.