LWA-2026-11142 confirmed malware

knip-bun@99.9.1

Malicious code in knip-bun (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

knip-bun@99.9.1 is an empty package (index.js exports an empty object) whose only dependency, "ltidisafe", is fetched at install time from a non-registry Google Cloud Storage URL: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]6[.]8[.]tgz. Installing this package downloads and installs an arbitrary tarball from that attacker-controlled bucket, executing its contents on the installer's machine. The package name and high version (99.9.1) mimic the legitimate knip tool to lure installs.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 05:27 AM
analyzed
Aug 13, 2026, 05:27 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.