LWA-2026-11143 confirmed malware

in-install@99.9.1

Malicious code in in-install (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

in-install@99.9.1 is an empty package (index.js exports an empty object, no code, no lifecycle hooks) whose only dependency, ltidisafe, is fetched at install time from a non-registry Google Cloud Storage URL: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]6[.]9[.]tgz. The dependency is not published on the npm registry, so its tarball contents are unverifiable and controlled by the package author. Installing this package pulls and installs an arbitrary, unverifiable tarball from an external CDN host.

analyzed by
Leitwacht
first seen
Aug 13, 2026, 05:28 AM
analyzed
Aug 13, 2026, 05:28 AM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.