LWA-2026-11141 confirmed malware
cspell-esm@99.9.1
Malicious code in cspell-esm (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
cspell-esm@99.9.1 is an empty package (index.js exports an empty object) that installs a dependency named ltidisafe fetched from a non-registry Google Cloud Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]6[.]7[.]tgz). The package name mimics the legitimate cspell spell-checker and is published at version 99.9.1, and the ltidisafe dependency is not available on the npm registry, so its contents are delivered entirely from the external CDN bucket at install time.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 05:26 AM
- analyzed
- Aug 13, 2026, 05:26 AM
Related advisories
- resolve-audit@99.9.1
- eslint-generate-prerelease@99.9.1
- mutex-forge@2.0.1
- internallib_v392@1.0.3
- prediction-trader@2.3.0
- external-process-live-log@13.5.2
- kit-map-vim@1.0.0
- velora-kit@12.0.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.