@visma-net-platform/module-navigator@99.9.1
Malicious code in @visma-net-platform/module-navigator (npm)
Analysis
Textbook dependency confusion stub: @visma-net-platform/module-navigator@99.9.1 impersonates a real enterprise namespace (Visma AS, Norway), published at version 99.9.1 by throwaway account [account]. The package contains a 35-byte stub (module.exports = {}) with zero functionality. The sole dependency "ltidisafe" points to hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-2[.]3[.]4[.]tgz — a remote GCS-hosted tarball allowing arbitrary code execution on npm install. This is designed to hijack installs in any project that trusts the @visma-net-platform scope, deploying arbitrary payload from the external bucket. No token-theft markers found in the stub itself (the payload vector is the external tarball). Needs human review for npm takedown.
- analyzed by
- Leitwacht
- first seen
- May 29, 2026, 01:12 AM
- analyzed
- May 29, 2026, 09:48 PM
Related advisories
- @visonum/network-quality-sdk@99.9.9
- @open-banking/cabinet-providers@999.9.5
- @easy-entry/landing-routes@99.9.5
- @easy-entry/outside-registration-fop-navigator@99.9.5
- @easy-entry/routes@99.9.5
- @shell-cabinet/routes@99.9.5
- @shell-landing/routes@99.9.5
- @veertly/web-app@99.9.9
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.