gunzip-js@99.9.1
Malicious code in gunzip-js (npm)
T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer
Analysis
gunzip-js@99.9.1 is an empty stub package (index.js exports an empty object) that declares a dependency "ltidisafe" fetched at install time from an off-registry Google Cloud Storage CDN: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]7[.]2[.]tgz. The dependency tarball is attacker-controlled and is downloaded and installed from the CDN rather than the npm registry, giving the publisher arbitrary code execution on the installer's machine during install.
- analyzed by
- Leitwacht
- first seen
- Aug 15, 2026, 02:28 PM
- analyzed
- Aug 15, 2026, 02:29 PM
Related advisories
- @mrzkyzdnii/baileys@0.3.18-mrzkyzdnii.2
- tailwind-utility-kit@1.3.2
- postcss-initialize-provider@3.0.4
- mutex-thread@1.3.0
- tailwind-plugin-kit@1.3.2
- tailwind-toolkit@1.3.2
- @cdnshell/loader@0.0.1
- bootstrap-custom-ui@5.7.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.