LWA-2026-11142 confirmed malware
knip-bun@99.9.1
Malicious code in knip-bun (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
knip-bun@99.9.1 is an empty package (index.js exports an empty object) whose only dependency, "ltidisafe", is fetched at install time from a non-registry Google Cloud Storage URL: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]6[.]8[.]tgz. Installing this package downloads and installs an arbitrary tarball from that attacker-controlled bucket, executing its contents on the installer's machine. The package name and high version (99.9.1) mimic the legitimate knip tool to lure installs.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 05:27 AM
- analyzed
- Aug 13, 2026, 05:27 AM
Related advisories
- cspell-esm@99.9.1
- resolve-audit@99.9.1
- eslint-generate-prerelease@99.9.1
- mutex-forge@2.0.1
- internallib_v392@1.0.3
- prediction-trader@2.3.0
- external-process-live-log@13.5.2
- kit-map-vim@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.