LWA-2026-11329 MAL-2026-14056 ↗ confirmed malware

gunzip-js@99.9.1

Malicious code in gunzip-js (npm)

T1195.002 · Compromise Software Supply ChainT1105 · Ingress Tool Transfer

Analysis

gunzip-js@99.9.1 is an empty stub package (index.js exports an empty object) that declares a dependency "ltidisafe" fetched at install time from an off-registry Google Cloud Storage CDN: hxxps://ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3[.]7[.]2[.]tgz. The dependency tarball is attacker-controlled and is downloaded and installed from the CDN rather than the npm registry, giving the publisher arbitrary code execution on the installer's machine during install.

analyzed by
Leitwacht
first seen
Aug 15, 2026, 02:28 PM
analyzed
Aug 15, 2026, 02:29 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.