LWA-2026-11141 confirmed malware

cspell-esm@99.9.1

Malicious code in cspell-esm (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

cspell-esm@99.9.1 is an empty package (index.js exports an empty object) that installs a dependency named ltidisafe fetched from a non-registry Google Cloud Storage URL (hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]6[.]7[.]tgz). The package name mimics the legitimate cspell spell-checker and is published at version 99.9.1, and the ltidisafe dependency is not available on the npm registry, so its contents are delivered entirely from the external CDN bucket at install time.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 05:26 AM
analyzed
Aug 13, 2026, 05:26 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.