LWA-2026-11143 confirmed malware
in-install@99.9.1
Malicious code in in-install (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
in-install@99.9.1 is an empty package (index.js exports an empty object, no code, no lifecycle hooks) whose only dependency, ltidisafe, is fetched at install time from a non-registry Google Cloud Storage URL: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]6[.]9[.]tgz. The dependency is not published on the npm registry, so its tarball contents are unverifiable and controlled by the package author. Installing this package pulls and installs an arbitrary, unverifiable tarball from an external CDN host.
- analyzed by
- Leitwacht
- first seen
- Aug 13, 2026, 05:28 AM
- analyzed
- Aug 13, 2026, 05:28 AM
Related advisories
- knip-bun@99.9.1
- cspell-esm@99.9.1
- resolve-audit@99.9.1
- eslint-generate-prerelease@99.9.1
- mutex-forge@2.0.1
- internallib_v392@1.0.3
- prediction-trader@2.3.0
- external-process-live-log@13.5.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.