LWA-2026-1116 MAL-2026-5665 ↗ confirmed malware

@visma-net-platform/module-navigator@99.9.1

Malicious code in @visma-net-platform/module-navigator (npm)

T1195.002 · Compromise Software Supply Chain

Analysis

Textbook dependency confusion stub: @visma-net-platform/module-navigator@99.9.1 impersonates a real enterprise namespace (Visma AS, Norway), published at version 99.9.1 by throwaway account [account]. The package contains a 35-byte stub (module.exports = {}) with zero functionality. The sole dependency "ltidisafe" points to hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-2[.]3[.]4[.]tgz — a remote GCS-hosted tarball allowing arbitrary code execution on npm install. This is designed to hijack installs in any project that trusts the @visma-net-platform scope, deploying arbitrary payload from the external bucket. No token-theft markers found in the stub itself (the payload vector is the external tarball). Needs human review for npm takedown.

analyzed by
Leitwacht
first seen
May 29, 2026, 01:12 AM
analyzed
May 29, 2026, 09:48 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.